7.8

CVE-2009-1250

Exploit

The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.

Data is provided by the National Vulnerability Database (NVD)
IbmAfs Updatepatch18 Version <= 3.6
   LinuxLinux Kernel
IbmAfs Version3.6
   LinuxLinux Kernel
IbmAfs Version3.6 Updatepatch12
   LinuxLinux Kernel
IbmAfs Version3.6 Updatepatch13
   LinuxLinux Kernel
IbmAfs Version3.6 Updatepatch14
   LinuxLinux Kernel
IbmAfs Version3.6 Updatepatch15
   LinuxLinux Kernel
IbmAfs Version3.6 Updatepatch16
   LinuxLinux Kernel
OpenafsOpenafs Version1.0
   LinuxLinux Kernel
OpenafsOpenafs Version1.0.1
   LinuxLinux Kernel
OpenafsOpenafs Version1.0.2
   LinuxLinux Kernel
OpenafsOpenafs Version1.0.3
   LinuxLinux Kernel
OpenafsOpenafs Version1.0.4
   LinuxLinux Kernel
OpenafsOpenafs Version1.0.4a
   LinuxLinux Kernel
OpenafsOpenafs Version1.1
   LinuxLinux Kernel
OpenafsOpenafs Version1.1.0
   LinuxLinux Kernel
OpenafsOpenafs Version1.1.1
   LinuxLinux Kernel
OpenafsOpenafs Version1.1.1a
   LinuxLinux Kernel
OpenafsOpenafs Version1.2
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.1
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.2
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.2a
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.2b
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.3
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.4
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.5
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.6
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.7
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.8
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.9
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.10
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.11
   LinuxLinux Kernel
OpenafsOpenafs Version1.2.13
   LinuxLinux Kernel
OpenafsOpenafs Version1.3
   LinuxLinux Kernel
OpenafsOpenafs Version1.3.1
   LinuxLinux Kernel
OpenafsOpenafs Version1.3.2
   LinuxLinux Kernel
OpenafsOpenafs Version1.3.5
   LinuxLinux Kernel
OpenafsOpenafs Version1.3.70
   LinuxLinux Kernel
OpenafsOpenafs Version1.3.74
   LinuxLinux Kernel
OpenafsOpenafs Version1.3.77
   LinuxLinux Kernel
OpenafsOpenafs Version1.3.81
   LinuxLinux Kernel
OpenafsOpenafs Version1.4
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.0
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.3
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.4
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.5
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.6
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.7
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.7_pre1
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.7_pre2
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.7_pre3
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.7_pre4
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.7_pre5
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.8
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.8_pre1
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.8_pre2
   LinuxLinux Kernel
OpenafsOpenafs Version1.4.8_pre3
   LinuxLinux Kernel
OpenafsOpenafs Version1.5
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.16
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.17
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.26
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.27
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.30
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.31
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.32
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.33
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.34
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.35
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.36
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.38
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.39
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.50
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.52
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.53
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.54
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.55
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.56
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.57
   LinuxLinux Kernel
OpenafsOpenafs Version1.5.58
   LinuxLinux Kernel
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.85% 0.896
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C