OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2) fileserver vice partition, or (3) certain RPC responses.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2016/12/02/9 | patch mailing list third party advisory |
https://www.openafs.org/pages/security/OPENAFS-SA-2016-003.txt | vendor advisory |
http://www.securityfocus.com/bid/94651 | third party advisory vdb entry |