Vulnerability Name: | CVE-2019-18601 (CCN-170438) | ||||||||||||||||
Assigned: | 2019-10-22 | ||||||||||||||||
Published: | 2019-10-22 | ||||||||||||||||
Updated: | 2019-11-06 | ||||||||||||||||
Summary: | OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to crash a database server within the SVOTE_Debug RPC handler. | ||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-502 | ||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-18601 Source: XF Type: UNKNOWN openafs-cve201918601-dos(170438) Source: MLIST Type: UNKNOWN [debian-lts-announce] 20191106 [SECURITY] [DLA 1982-1] openafs security update Source: CCN Type: OpenAFS Security Advisory 2019-003 database server crash from unserialized data access Source: MISC Type: Vendor Advisory https://openafs.org/pages/security/OPENAFS-SA-2019-003.txt | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |