HIGH
The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro
Published Apr 9, 2009
7.8
HIGHCVSS 2.0
EPSS 3.98%
Description
The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.
Affected products
No data.
AND
OR
- ≤ 3.6
- 3.6
- 3.6
- 3.6
- 3.6
- 3.6
- 3.6
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.4a
- 1.1
- 1.1.0
- 1.1.1
- 1.1.1a
- 1.2
- 1.2.1
- 1.2.2
- 1.2.2a
- 1.2.2b
- 1.2.3
- 1.2.4
- 1.2.5
- 1.2.6
- 1.2.7
- 1.2.8
- 1.2.9
- 1.2.10
- 1.2.11
- 1.2.13
- 1.3
- 1.3.1
- 1.3.2
- 1.3.5
- 1.3.70
- 1.3.74
- 1.3.77
- 1.3.81
- 1.4
- 1.4.0
- 1.4.3
- 1.4.4
- 1.4.5
- 1.4.6
- 1.4.7
- 1.4.7_pre1
- 1.4.7_pre2
- 1.4.7_pre3
- 1.4.7_pre4
- 1.4.7_pre5
- 1.4.8
- 1.4.8_pre1
- 1.4.8_pre2
- 1.4.8_pre3
- 1.5
- 1.5.16
- 1.5.17
- 1.5.26
- 1.5.27
- 1.5.30
- 1.5.31
- 1.5.32
- 1.5.33
- 1.5.34
- 1.5.35
- 1.5.36
- 1.5.38
- 1.5.39
- 1.5.50
- 1.5.52
- 1.5.53
- 1.5.54
- 1.5.55
- 1.5.56
- 1.5.57
- 1.5.58
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (14)
- http://secunia.com/advisories/34655 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34684 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/36310 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42896 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201101-05.xml vendor-advisoryx_refsource_GENTOO
- http://www-01.ibm.com/support/docview.wss?uid=swg21396389 x_refsource_CONFIRM
- http://www-1.ibm.com/support/docview.wss?uid=swg1ID71123 vendor-advisoryx_refsource_AIXAPAR
- http://www.debian.org/security/2009/dsa-1768 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:099 vendor-advisoryx_refsource_MANDRIVA
- http://www.openafs.org/security/OPENAFS-SA-2009-002.txt x_refsource_CONFIRM
- http://www.openafs.org/security/openafs-sa-2009-002.patch x_refsource_CONFIRMExploit
- http://www.securityfocus.com/bid/34404 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2009/0984 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0117 vdb-entryx_refsource_VUPEN
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 9, 2009
Updated Aug 7, 2024
Reserved Apr 6, 2009
Link CVE-2009-1250
CISA Vulnrichment
Updated n/a