Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-10396

Опубликовано: 14 нояб. 2024
Источник: debian

Описание

An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store garbage data in the audit log. Malformed ACLs provided in responses to client FetchACL RPCs can cause client processes to crash and possibly expose uninitialized memory into other ACLs stored on the server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openafsfixed1.8.13-1package

Примечания

  • http://openafs.org/pages/security/OPENAFS-SA-2024-002.txt

  • https://lists.openafs.org/pipermail/openafs-devel/2024-November/020961.html

  • https://www.openafs.org/pages/security/openafs-sa-2024-002-stable16.patch (openafs-stable-1_6_25)

  • https://www.openafs.org/pages/security/openafs-sa-2024-002-stable18.patch (openafs-stable-1_8_13)

  • http://git.openafs.org/?p=openafs.git;a=commit;h=a07e50726df09c49dfe7b953c3e49eb98f310c09 (openafs-stable-1_8_13)

  • http://git.openafs.org/?p=openafs.git;a=commit;h=f74f960a18f559e683d6a1f5104e43c3ca93ecb8 (openafs-stable-1_8_13)

  • http://git.openafs.org/?p=openafs.git;a=commit;h=1e6e813188ecce62eb7af19385d911f63469bdb6 (openafs-stable-1_8_13)

  • http://git.openafs.org/?p=openafs.git;a=commit;h=d66caf8c04878724001839317637445708edef2c (openafs-stable-1_8_13)

  • http://git.openafs.org/?p=openafs.git;a=commit;h=ee020f7cba7d82bc3d4b468210b5052af53c5db5 (openafs-stable-1_8_13)

  • http://git.openafs.org/?p=openafs.git;a=commit;h=bb01d76a2095baa65880bdc5d504e7a198958265 (openafs-stable-1_8_13)

  • http://git.openafs.org/?p=openafs.git;a=commit;h=64068705b15661a8d4e0b9f9f2ad4aec34ed51a7 (openafs-stable-1_8_13)

  • http://git.openafs.org/?p=openafs.git;a=commit;h=a96a3160f5425125588f39f5ac612df3ef9b9a8a (openafs-stable-1_8_13)

  • http://git.openafs.org/?p=openafs.git;a=commit;h=a9ede52673b8c8abbfc2577ac6987a8a5686206f (openafs-stable-1_8_13)

  • http://git.openafs.org/?p=openafs.git;a=commit;h=21941c0ab2d28fa3a074f46e4d448d518a7c1b8a (openafs-stable-1_8_13)

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 года назад

An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store garbage data in the audit log. Malformed ACLs provided in responses to client FetchACL RPCs can cause client processes to crash and possibly expose uninitialized memory into other ACLs stored on the server.

CVSS3: 6.5
nvd
около 1 года назад

An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store garbage data in the audit log. Malformed ACLs provided in responses to client FetchACL RPCs can cause client processes to crash and possibly expose uninitialized memory into other ACLs stored on the server.

github
около 1 года назад

An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store garbage data in the audit log. Malformed ACLs provided in responses to client FetchACL RPCs can cause client processes to crash and possibly expose uninitialized memory into other ACLs stored on the server.