Integer overflow in ptserver in OpenAFS before 1.6.2 allows remote attackers to cause a denial of service (crash) via a large list from the IdToName RPC, which triggers a heap-based buffer overflow.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://secunia.com/advisories/52480 | third party advisory permissions required |
https://exchange.xforce.ibmcloud.com/vulnerabilities/82585 | vdb entry |
http://secunia.com/advisories/52342 | third party advisory permissions required |
http://www.debian.org/security/2013/dsa-2638 | vendor advisory |
http://www.securityfocus.com/bid/58300 | vdb entry third party advisory |
http://www.openafs.org/pages/security/OPENAFS-SA-2013-002.txt | vendor advisory |
http://www.mandriva.com/security/advisories?name=MDVSA-2014:244 | vendor advisory broken link |