Denial of Service (DoS) Affecting openafs package, versions [1.0,1.5.58]


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
4.29% (93rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-OPENAFS-2381809
  • published26 Jan 2022
  • disclosed9 Apr 2009
  • creditUnknown

Introduced: 9 Apr 2009

CVE-2009-1250  (opens in a new tab)
CWE-189  (opens in a new tab)

How to fix?

There is no fixed version for openafs.

Overview

Affected versions of this package are vulnerable to Denial of Service (DoS). The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.

References

CVSS Scores

version 3.1