CVE-2009-1251
Published: 9 April 2009
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via an RX response containing more data than specified in a request, related to use of XDR arrays.
Priority
Status
Package | Release | Status |
---|---|---|
openafs Launchpad, Ubuntu, Debian |
dapper |
Released
(1.4.1-2+ubuntu0.1)
|
gutsy |
Ignored
(end of life, was needs-triage)
|
|
hardy |
Released
(1.4.6.dfsg1-2+ubuntu0.1)
|
|
intrepid |
Released
(1.4.7.dfsg1-6+ubuntu0.1)
|
|
upstream |
Needs triage
|
|
Patches: upstream: http://www.openafs.org/security/openafs-sa-2009-001.patch |