Paketname
openafs
Datum
2009-04-27
Advisory ID
MDVSA-2009:099
Betroffene Versionen
2009.0 x86_64 , 2009.0 i586 , 2008.1 x86_64 , 2008.1 i586

Problembeschreibung

Multiple vulnerabilities has been found and corrected in openafs:

The cache manager in the client in OpenAFS 1.0 through 1.4.8 and
1.5.0 through 1.5.58 on Linux allows remote attackers to cause a
denial of service (system crash) via an RX response with a large
error-code value that is interpreted as a pointer and dereferenced,
related to use of the ERR_PTR macro (CVE-2009-1250).

Heap-based buffer overflow in the cache manager in the client in
OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms
allows remote attackers to cause a denial of service (system crash)
or possibly execute arbitrary code via an RX response containing
more data than specified in a request, related to use of XDR arrays
(CVE-2009-1251).

The updated packages have been patched to correct these issues.

Aktualisierte Pakete

2009.0 x86_64

 b3de2c51a9ebe9725734eeae29ccdc72  2009.0/x86_64/dkms-libafs-1.4.7-5.2mdv2009.0.x86_64.rpm
 37420ff8ce6130ee9d9a02adea275e82  2009.0/x86_64/lib64openafs1-1.4.7-5.2mdv2009.0.x86_64.rpm
 7998ffc68e1ebfbda40f4da9a64987f3  2009.0/x86_64/lib64openafs-devel-1.4.7-5.2mdv2009.0.x86_64.rpm
 2d84886e35e0e2b3bb3071fd6cce0c76  2009.0/x86_64/openafs-1.4.7-5.2mdv2009.0.x86_64.rpm
 2309fcaac310158fa454b37fb7d5d630  2009.0/x86_64/openafs-client-1.4.7-5.2mdv2009.0.x86_64.rpm
 794c55cc04aa8a0e24b24cb86b3ff081  2009.0/x86_64/openafs-doc-1.4.7-5.2mdv2009.0.x86_64.rpm
 3dbb9883458befe1bf8fc23b4bf79462  2009.0/x86_64/openafs-server-1.4.7-5.2mdv2009.0.x86_64.rpm 
 47ab1221f47247749f364ab5fc7b7943  2009.0/SRPMS/openafs-1.4.7-5.2mdv2009.0.src.rpm

2009.0 i586

 8e67ac1efcf75df028b57af319fa24f8  2009.0/i586/dkms-libafs-1.4.7-5.2mdv2009.0.i586.rpm
 56144e99b69a88fee79d7bc7599c6d8d  2009.0/i586/libopenafs1-1.4.7-5.2mdv2009.0.i586.rpm
 62d1c441319f414446b04175ecdd8c17  2009.0/i586/libopenafs-devel-1.4.7-5.2mdv2009.0.i586.rpm
 ddbd27f1a3312f2fe82ec8becc0973ee  2009.0/i586/openafs-1.4.7-5.2mdv2009.0.i586.rpm
 f21aff47d3be5c40282c1711a728bf17  2009.0/i586/openafs-client-1.4.7-5.2mdv2009.0.i586.rpm
 891879d3914066636b3d62bfea6639f2  2009.0/i586/openafs-doc-1.4.7-5.2mdv2009.0.i586.rpm
 15586a9774f6152e79448446a2ee54ab  2009.0/i586/openafs-server-1.4.7-5.2mdv2009.0.i586.rpm 
 47ab1221f47247749f364ab5fc7b7943  2009.0/SRPMS/openafs-1.4.7-5.2mdv2009.0.src.rpm

2008.1 x86_64

 9071824db5b9a7966d9bc1087479bcff  2008.1/x86_64/dkms-libafs-1.4.6-2.1mdv2008.1.x86_64.rpm
 08d0bbf0b02d19ba340b4979c6ca3fbf  2008.1/x86_64/lib64openafs1-1.4.6-2.1mdv2008.1.x86_64.rpm
 423d5fffa2c1c689cfcd825360366c33  2008.1/x86_64/lib64openafs-devel-1.4.6-2.1mdv2008.1.x86_64.rpm
 ac6cd4115b32f3f450c145d75fe170d4  2008.1/x86_64/openafs-1.4.6-2.1mdv2008.1.x86_64.rpm
 992723a9903ef944d77bd59bed6d93d4  2008.1/x86_64/openafs-client-1.4.6-2.1mdv2008.1.x86_64.rpm
 2c53bca13c5eeb3f343e0d011b369b38  2008.1/x86_64/openafs-doc-1.4.6-2.1mdv2008.1.x86_64.rpm
 423bc5d809f47439030e16f852b8077d  2008.1/x86_64/openafs-server-1.4.6-2.1mdv2008.1.x86_64.rpm 
 dcdcbf5ff5c3e8a9c017f8dd8cd943c3  2008.1/SRPMS/openafs-1.4.6-2.1mdv2008.1.src.rpm

2008.1 i586

 cb96049086b295f4a3e5685281dccad2  2008.1/i586/dkms-libafs-1.4.6-2.1mdv2008.1.i586.rpm
 73a5527fc50409b85b1621c298777c57  2008.1/i586/libopenafs1-1.4.6-2.1mdv2008.1.i586.rpm
 94efebaea82ddd7613b395e624951d97  2008.1/i586/libopenafs-devel-1.4.6-2.1mdv2008.1.i586.rpm
 4009bef901826cc2aeb567b689b060b4  2008.1/i586/openafs-1.4.6-2.1mdv2008.1.i586.rpm
 c322e6b2b3ba92dbf26354fd5139614c  2008.1/i586/openafs-client-1.4.6-2.1mdv2008.1.i586.rpm
 85b4aa3bf3cf6a44713e60df4ebd154a  2008.1/i586/openafs-doc-1.4.6-2.1mdv2008.1.i586.rpm
 d3898f18f4702b3eadff9d1c9a651324  2008.1/i586/openafs-server-1.4.6-2.1mdv2008.1.i586.rpm 
 dcdcbf5ff5c3e8a9c017f8dd8cd943c3  2008.1/SRPMS/openafs-1.4.6-2.1mdv2008.1.src.rpm

Referenzen