Lucene search

K
cveMitreCVE-2009-1250
HistoryApr 09, 2009 - 12:30 a.m.

CVE-2009-1250

2009-04-0900:30:00
CWE-189
mitre
web.nvd.nist.gov
54
openafs
ibm afs
denial of service
system crash
cve-2009-1250
nvd

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.2

Confidence

Low

EPSS

0.043

Percentile

92.3%

The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.

Affected configurations

Nvd
Node
ibmafsRange≀3.6patch18
OR
ibmafsMatch3.6
OR
ibmafsMatch3.6patch12
OR
ibmafsMatch3.6patch13
OR
ibmafsMatch3.6patch14
OR
ibmafsMatch3.6patch15
OR
ibmafsMatch3.6patch16
OR
openafsopenafsMatch1.0
OR
openafsopenafsMatch1.0.1
OR
openafsopenafsMatch1.0.2
OR
openafsopenafsMatch1.0.3
OR
openafsopenafsMatch1.0.4
OR
openafsopenafsMatch1.0.4a
OR
openafsopenafsMatch1.1
OR
openafsopenafsMatch1.1.0
OR
openafsopenafsMatch1.1.1
OR
openafsopenafsMatch1.1.1a
OR
openafsopenafsMatch1.2
OR
openafsopenafsMatch1.2.1
OR
openafsopenafsMatch1.2.2
OR
openafsopenafsMatch1.2.2a
OR
openafsopenafsMatch1.2.2b
OR
openafsopenafsMatch1.2.3
OR
openafsopenafsMatch1.2.4
OR
openafsopenafsMatch1.2.5
OR
openafsopenafsMatch1.2.6
OR
openafsopenafsMatch1.2.7
OR
openafsopenafsMatch1.2.8
OR
openafsopenafsMatch1.2.9
OR
openafsopenafsMatch1.2.10
OR
openafsopenafsMatch1.2.11
OR
openafsopenafsMatch1.2.13
OR
openafsopenafsMatch1.3
OR
openafsopenafsMatch1.3.1
OR
openafsopenafsMatch1.3.2
OR
openafsopenafsMatch1.3.5
OR
openafsopenafsMatch1.3.70
OR
openafsopenafsMatch1.3.74
OR
openafsopenafsMatch1.3.77
OR
openafsopenafsMatch1.3.81
OR
openafsopenafsMatch1.4
OR
openafsopenafsMatch1.4.0
OR
openafsopenafsMatch1.4.3
OR
openafsopenafsMatch1.4.4
OR
openafsopenafsMatch1.4.5
OR
openafsopenafsMatch1.4.6
OR
openafsopenafsMatch1.4.7
OR
openafsopenafsMatch1.4.7_pre1
OR
openafsopenafsMatch1.4.7_pre2
OR
openafsopenafsMatch1.4.7_pre3
OR
openafsopenafsMatch1.4.7_pre4
OR
openafsopenafsMatch1.4.7_pre5
OR
openafsopenafsMatch1.4.8
OR
openafsopenafsMatch1.4.8_pre1
OR
openafsopenafsMatch1.4.8_pre2
OR
openafsopenafsMatch1.4.8_pre3
OR
openafsopenafsMatch1.5
OR
openafsopenafsMatch1.5.16
OR
openafsopenafsMatch1.5.17
OR
openafsopenafsMatch1.5.26
OR
openafsopenafsMatch1.5.27
OR
openafsopenafsMatch1.5.30
OR
openafsopenafsMatch1.5.31
OR
openafsopenafsMatch1.5.32
OR
openafsopenafsMatch1.5.33
OR
openafsopenafsMatch1.5.34
OR
openafsopenafsMatch1.5.35
OR
openafsopenafsMatch1.5.36
OR
openafsopenafsMatch1.5.38
OR
openafsopenafsMatch1.5.39
OR
openafsopenafsMatch1.5.50
OR
openafsopenafsMatch1.5.52
OR
openafsopenafsMatch1.5.53
OR
openafsopenafsMatch1.5.54
OR
openafsopenafsMatch1.5.55
OR
openafsopenafsMatch1.5.56
OR
openafsopenafsMatch1.5.57
OR
openafsopenafsMatch1.5.58
AND
linuxlinux_kernel
VendorProductVersionCPE
ibmafs*cpe:2.3:a:ibm:afs:*:patch18:*:*:*:*:*:*
ibmafs3.6cpe:2.3:a:ibm:afs:3.6:*:*:*:*:*:*:*
ibmafs3.6cpe:2.3:a:ibm:afs:3.6:patch12:*:*:*:*:*:*
ibmafs3.6cpe:2.3:a:ibm:afs:3.6:patch13:*:*:*:*:*:*
ibmafs3.6cpe:2.3:a:ibm:afs:3.6:patch14:*:*:*:*:*:*
ibmafs3.6cpe:2.3:a:ibm:afs:3.6:patch15:*:*:*:*:*:*
ibmafs3.6cpe:2.3:a:ibm:afs:3.6:patch16:*:*:*:*:*:*
openafsopenafs1.0cpe:2.3:a:openafs:openafs:1.0:*:*:*:*:*:*:*
openafsopenafs1.0.1cpe:2.3:a:openafs:openafs:1.0.1:*:*:*:*:*:*:*
openafsopenafs1.0.2cpe:2.3:a:openafs:openafs:1.0.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 791

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.2

Confidence

Low

EPSS

0.043

Percentile

92.3%