CVE-2018-16949

NameCVE-2018-16949
DescriptionAn issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables were implemented as unbounded array types, limited only by the inherent 32-bit length field to 4 GB. An unauthenticated attacker could send, or claim to send, large input values and consume server resources waiting for those inputs, denying service to other valid connections.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1513-1, DSA-4302-1
NVD severitymedium (attack range: remote)
Debian Bugs908616

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openafs (PTS)jessie1.6.9-2+deb8u7vulnerable
jessie (security)1.6.9-2+deb8u8fixed
stretch (security), stretch1.6.20-2+deb9u2fixed
buster, sid1.8.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openafssource(unstable)1.8.2-1medium908616
openafssourcejessie1.6.9-2+deb8u8mediumDLA-1513-1
openafssourcestretch1.6.20-2+deb9u2mediumDSA-4302-1

Notes

http://openafs.org/pages/security/OPENAFS-SA-2018-003.txt

Search for package or bug name: Reporting problems