Vulnerability CVE-2015-3286


Published: 2015-08-12

Description:
Buffer overflow in the Solaris kernel extension in OpenAFS before 1.6.13 allows local users to cause a denial of service (panic or deadlock) or possibly have other unspecified impact via a large group list when joining a PAG.

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Openafs -> Openafs 

 References:
http://www.openafs.org/pages/security/OPENAFS-SA-2015-005.txt
http://www.securitytracker.com/id/1033262
https://lists.openafs.org/pipermail/openafs-announce/2015/000486.html
https://www.openafs.org/dl/openafs/1.6.13/RELNOTES-1.6.13

Copyright 2024, cxsecurity.com

 

Back to Top