CVE-2018-16949

NameCVE-2018-16949
DescriptionAn issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables were implemented as unbounded array types, limited only by the inherent 32-bit length field to 4 GB. An unauthenticated attacker could send, or claim to send, large input values and consume server resources waiting for those inputs, denying service to other valid connections.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1513-1, DSA-4302-1
NVD severitymedium
Debian Bugs908616

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openafs (PTS)stretch (security), stretch1.6.20-2+deb9u2fixed
buster1.8.2-1fixed
bullseye, sid1.8.6-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openafssourcejessie1.6.9-2+deb8u8DLA-1513-1
openafssourcestretch1.6.20-2+deb9u2DSA-4302-1
openafssource(unstable)1.8.2-1908616

Notes

http://openafs.org/pages/security/OPENAFS-SA-2018-003.txt

Search for package or bug name: Reporting problems