Vulnerabilites related to ibm - afs
Vulnerability from fkie_nvd
Published
2009-04-09 00:30
Modified
2025-04-09 00:30
Severity ?
Summary
The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.
References
cve@mitre.orghttp://secunia.com/advisories/34655
cve@mitre.orghttp://secunia.com/advisories/34684
cve@mitre.orghttp://secunia.com/advisories/36310
cve@mitre.orghttp://secunia.com/advisories/42896
cve@mitre.orghttp://security.gentoo.org/glsa/glsa-201101-05.xml
cve@mitre.orghttp://www-01.ibm.com/support/docview.wss?uid=swg21396389
cve@mitre.orghttp://www-1.ibm.com/support/docview.wss?uid=swg1ID71123
cve@mitre.orghttp://www.debian.org/security/2009/dsa-1768
cve@mitre.orghttp://www.mandriva.com/security/advisories?name=MDVSA-2009:099
cve@mitre.orghttp://www.openafs.org/security/OPENAFS-SA-2009-002.txt
cve@mitre.orghttp://www.openafs.org/security/openafs-sa-2009-002.patchExploit
cve@mitre.orghttp://www.securityfocus.com/bid/34404
cve@mitre.orghttp://www.vupen.com/english/advisories/2009/0984
cve@mitre.orghttp://www.vupen.com/english/advisories/2011/0117
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/34655
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/34684
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/36310
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/42896
af854a3a-2127-422b-91ae-364da2661108http://security.gentoo.org/glsa/glsa-201101-05.xml
af854a3a-2127-422b-91ae-364da2661108http://www-01.ibm.com/support/docview.wss?uid=swg21396389
af854a3a-2127-422b-91ae-364da2661108http://www-1.ibm.com/support/docview.wss?uid=swg1ID71123
af854a3a-2127-422b-91ae-364da2661108http://www.debian.org/security/2009/dsa-1768
af854a3a-2127-422b-91ae-364da2661108http://www.mandriva.com/security/advisories?name=MDVSA-2009:099
af854a3a-2127-422b-91ae-364da2661108http://www.openafs.org/security/OPENAFS-SA-2009-002.txt
af854a3a-2127-422b-91ae-364da2661108http://www.openafs.org/security/openafs-sa-2009-002.patchExploit
af854a3a-2127-422b-91ae-364da2661108http://www.securityfocus.com/bid/34404
af854a3a-2127-422b-91ae-364da2661108http://www.vupen.com/english/advisories/2009/0984
af854a3a-2127-422b-91ae-364da2661108http://www.vupen.com/english/advisories/2011/0117
Impacted products
Vendor Product Version
ibm afs *
ibm afs 3.6
ibm afs 3.6
ibm afs 3.6
ibm afs 3.6
ibm afs 3.6
ibm afs 3.6
openafs openafs 1.0
openafs openafs 1.0.1
openafs openafs 1.0.2
openafs openafs 1.0.3
openafs openafs 1.0.4
openafs openafs 1.0.4a
openafs openafs 1.1
openafs openafs 1.1.0
openafs openafs 1.1.1
openafs openafs 1.1.1a
openafs openafs 1.2
openafs openafs 1.2.1
openafs openafs 1.2.2
openafs openafs 1.2.2a
openafs openafs 1.2.2b
openafs openafs 1.2.3
openafs openafs 1.2.4
openafs openafs 1.2.5
openafs openafs 1.2.6
openafs openafs 1.2.7
openafs openafs 1.2.8
openafs openafs 1.2.9
openafs openafs 1.2.10
openafs openafs 1.2.11
openafs openafs 1.2.13
openafs openafs 1.3
openafs openafs 1.3.1
openafs openafs 1.3.2
openafs openafs 1.3.5
openafs openafs 1.3.70
openafs openafs 1.3.74
openafs openafs 1.3.77
openafs openafs 1.3.81
openafs openafs 1.4
openafs openafs 1.4.0
openafs openafs 1.4.3
openafs openafs 1.4.4
openafs openafs 1.4.5
openafs openafs 1.4.6
openafs openafs 1.4.7
openafs openafs 1.4.7_pre1
openafs openafs 1.4.7_pre2
openafs openafs 1.4.7_pre3
openafs openafs 1.4.7_pre4
openafs openafs 1.4.7_pre5
openafs openafs 1.4.8
openafs openafs 1.4.8_pre1
openafs openafs 1.4.8_pre2
openafs openafs 1.4.8_pre3
openafs openafs 1.5
openafs openafs 1.5.16
openafs openafs 1.5.17
openafs openafs 1.5.26
openafs openafs 1.5.27
openafs openafs 1.5.30
openafs openafs 1.5.31
openafs openafs 1.5.32
openafs openafs 1.5.33
openafs openafs 1.5.34
openafs openafs 1.5.35
openafs openafs 1.5.36
openafs openafs 1.5.38
openafs openafs 1.5.39
openafs openafs 1.5.50
openafs openafs 1.5.52
openafs openafs 1.5.53
openafs openafs 1.5.54
openafs openafs 1.5.55
openafs openafs 1.5.56
openafs openafs 1.5.57
openafs openafs 1.5.58
linux linux_kernel *



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:afs:*:patch18:*:*:*:*:*:*",
              "matchCriteriaId": "4201D241-5784-46AC-AACD-5612EB4F08AB",
              "versionEndIncluding": "3.6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:ibm:afs:3.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "30616D7B-7047-4DB0-A259-1859619AC78B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:ibm:afs:3.6:patch12:*:*:*:*:*:*",
              "matchCriteriaId": "278D5804-4178-4946-AA4A-987540E82602",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:ibm:afs:3.6:patch13:*:*:*:*:*:*",
              "matchCriteriaId": "E41CEBB0-3A49-4652-AE91-D41A40DF92A6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:ibm:afs:3.6:patch14:*:*:*:*:*:*",
              "matchCriteriaId": "8E86AF64-34DB-4C1F-AAC7-BA44D5DDBF20",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:ibm:afs:3.6:patch15:*:*:*:*:*:*",
              "matchCriteriaId": "441D8AD1-5E83-4A48-9C5E-50E508C60B01",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:ibm:afs:3.6:patch16:*:*:*:*:*:*",
              "matchCriteriaId": "8B0EB239-580C-433D-8FAB-6BF0437D0755",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "DBC8B64A-B5A9-4F66-86AD-0288F8E3D62D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "BE08E0AC-71F8-456B-9E88-43E94A6A2F47",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.0.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "10CFD4A8-71AE-4F85-B86D-001461ECC2E4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.0.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "8CD3D4A8-934B-420A-AF4A-36DD16E2F851",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.0.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "9D7AD53C-917A-41CC-83CD-6DF825E2640E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.0.4a:*:*:*:*:*:*:*",
              "matchCriteriaId": "F6F84C9B-8073-4EBE-AA75-A373772A42EF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "8E921700-C76F-41EA-AA61-6F939ED329CB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.1.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "FC9A5221-2DBC-487A-9C6D-84EB9C95EB05",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.1.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "0BDBD251-3E96-4068-AD24-E5B1802769E9",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.1.1a:*:*:*:*:*:*:*",
              "matchCriteriaId": "23A07568-7B15-49F1-9163-40A0BFF38309",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "E8A18760-0921-475E-9104-4DF480697E96",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "CD01B5F6-7E91-4FE8-B345-42D58C786FCB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "34002792-689C-45B5-9B5A-94B5342AC20B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.2a:*:*:*:*:*:*:*",
              "matchCriteriaId": "3331166E-ABBA-4326-8EF4-88872B9824A3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.2b:*:*:*:*:*:*:*",
              "matchCriteriaId": "302A9220-4C73-4D69-8B62-B64A7E280B31",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "2B8FC287-D6D8-44BA-9125-3E64624ECDFF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "295C09E5-23C3-4F9E-80FC-B0C4EC34C846",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "0295B94D-BE71-4DA2-81C5-E5BBCF0E17AB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "2FBADEB7-0073-42EB-B53D-ADA227898493",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "F0951C53-C62A-4607-B6DB-E6B38DF3A5E5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "0813CDDB-FF48-4154-81F3-20873A6C6C45",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "6AAAE0E9-BB79-455F-A08E-AC83370DBD0E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "55B65ACE-3BA2-4B42-AEE8-8F647A6399F0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "C0E298D9-63FB-4818-A2F1-EDFC287625F7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.2.13:*:*:*:*:*:*:*",
              "matchCriteriaId": "E3F2EED9-29E6-41E9-A911-D6ED9A08643C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "299D4344-A1DB-4EC3-B1A2-5E07FB2B585F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.3.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "72BE26C0-4A71-43AE-B134-3CE6DE839349",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.3.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "DE590EA3-85F6-462A-BCC1-0550192F8F9C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.3.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "20DB0E2F-782F-4BA1-A81A-5DDDA8CF0A79",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.3.70:*:*:*:*:*:*:*",
              "matchCriteriaId": "3C1399FC-A356-4624-BBA6-059B797B4C2E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.3.74:*:*:*:*:*:*:*",
              "matchCriteriaId": "5D767864-04D5-4571-8B13-CD347ADB3ADA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.3.77:*:*:*:*:*:*:*",
              "matchCriteriaId": "C47CECE6-1BD8-4CC3-B1F8-A4A069004C8E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.3.81:*:*:*:*:*:*:*",
              "matchCriteriaId": "846D8776-DCDF-4BD0-A391-5546BD4B20C4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "58C9013E-A08B-441E-AE3F-C688793366FA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "E0F37635-C186-4D06-A79C-2A7AB0CFBAD9",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "CB1364B7-D564-4385-B7D7-67184E474712",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "EA3D7891-0B48-4C5D-B74B-6810FB4696F4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "2C3BF7B2-72FF-4756-A1CC-982A1CD0747C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "832A44D5-3851-4DC5-A37A-B3C356764B19",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "D6F42FFC-9EA1-471C-8E5F-F8860BB2EA06",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.7_pre1:*:*:*:*:*:*:*",
              "matchCriteriaId": "91E0060C-4C43-4B4C-88CE-01F5055A9193",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.7_pre2:*:*:*:*:*:*:*",
              "matchCriteriaId": "4F1A3516-7785-406E-83B2-96A0FF8461A3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.7_pre3:*:*:*:*:*:*:*",
              "matchCriteriaId": "F020E77C-8445-4BE8-A36E-A436102FE83B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.7_pre4:*:*:*:*:*:*:*",
              "matchCriteriaId": "39F16D28-5011-4CE3-A656-9F9908E760AD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.7_pre5:*:*:*:*:*:*:*",
              "matchCriteriaId": "1F1E040E-020D-4567-BF57-9A2DA7294CB3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "38D14A4C-D467-431A-A223-9383FD94EB12",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.8_pre1:*:*:*:*:*:*:*",
              "matchCriteriaId": "ED10F836-88BE-4832-BE5A-83AE0C798368",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.8_pre2:*:*:*:*:*:*:*",
              "matchCriteriaId": "CA22C60E-64A4-4340-A780-0C85BDACBB01",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.8_pre3:*:*:*:*:*:*:*",
              "matchCriteriaId": "F407281C-A813-4190-BBF1-FB93779681DC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "4C6BEEDA-C1FE-49BA-A829-BA3BBBED1AFC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.16:*:*:*:*:*:*:*",
              "matchCriteriaId": "39308049-0C20-4845-9803-529A85CB9682",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.17:*:*:*:*:*:*:*",
              "matchCriteriaId": "CAC63C9E-169F-40B5-A011-2A77B675875D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.26:*:*:*:*:*:*:*",
              "matchCriteriaId": "378F38A7-422C-4603-8120-42DB91C8B90D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.27:*:*:*:*:*:*:*",
              "matchCriteriaId": "69AC18EA-7DB6-4F68-95DD-637D557DDF0B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.30:*:*:*:*:*:*:*",
              "matchCriteriaId": "BFD8DE00-622E-42DC-B1C7-8B9C1300DEF2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.31:*:*:*:*:*:*:*",
              "matchCriteriaId": "A6FCFBC7-CDEF-402D-8C11-DD3D112B76CF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.32:*:*:*:*:*:*:*",
              "matchCriteriaId": "22ABC36E-79A7-41A6-8A80-CF3563EE640E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.33:*:*:*:*:*:*:*",
              "matchCriteriaId": "9E121D95-158B-446D-BECD-D90D348A8CE0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.34:*:*:*:*:*:*:*",
              "matchCriteriaId": "C2993321-45A6-496F-ADC3-B83E52B90ADD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.35:*:*:*:*:*:*:*",
              "matchCriteriaId": "4EA6732C-6108-40B1-B9D3-D11D9C18B225",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.36:*:*:*:*:*:*:*",
              "matchCriteriaId": "A93DE322-6843-4C9C-82F2-2E55FC5231DE",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.38:*:*:*:*:*:*:*",
              "matchCriteriaId": "52D0C9D5-009C-4153-AB84-1DC3191CAC72",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.39:*:*:*:*:*:*:*",
              "matchCriteriaId": "18AAA5FE-D9FE-40A8-804B-C86C2D865958",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.50:*:*:*:*:*:*:*",
              "matchCriteriaId": "ADCB63E5-D32E-41E3-958D-F1991318CFA5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.52:*:*:*:*:*:*:*",
              "matchCriteriaId": "7FDE6F07-DD16-4075-B7C4-4C3B9A194C8E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.53:*:*:*:*:*:*:*",
              "matchCriteriaId": "B0B8EC69-A4CD-42F8-AD25-ACE8DDAE7F02",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.54:*:*:*:*:*:*:*",
              "matchCriteriaId": "9F3B0624-435B-4A06-BC13-5B47C34E11E8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.55:*:*:*:*:*:*:*",
              "matchCriteriaId": "A8F90E76-4EF0-4E12-96F9-1007DF457277",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.56:*:*:*:*:*:*:*",
              "matchCriteriaId": "F3944EFB-9C8C-451E-A339-603FC617A352",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.57:*:*:*:*:*:*:*",
              "matchCriteriaId": "5B400BB8-53F2-4BC3-842B-42480B52D156",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.58:*:*:*:*:*:*:*",
              "matchCriteriaId": "5A1C5AD7-141A-4932-9A05-994B6CC69AC8",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "155AD4FB-E527-4103-BCEF-801B653DEA37",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro."
    },
    {
      "lang": "es",
      "value": "El gestor de cach\u00e9 en el cliente OpenAFS v1.0 hasta v1.4.8 y v1.5.0 hasta v1.5.58 en Linux, permite a atacantes remotos provocar una denegaci\u00f3n de servicio (ca\u00edda del sistema) a trav\u00e9s de una respuesta RX con un valor en el c\u00f3digo de error muy largo, lo que es interpretado como un puntero y desrefereciado, relativo al uso de la macro ERR_PTR."
    }
  ],
  "id": "CVE-2009-1250",
  "lastModified": "2025-04-09T00:30:58.490",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "HIGH",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "COMPLETE",
          "baseScore": 7.8,
          "confidentialityImpact": "NONE",
          "integrityImpact": "NONE",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "version": "2.0"
        },
        "exploitabilityScore": 10.0,
        "impactScore": 6.9,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ]
  },
  "published": "2009-04-09T00:30:00.313",
  "references": [
    {
      "source": "cve@mitre.org",
      "url": "http://secunia.com/advisories/34655"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://secunia.com/advisories/34684"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://secunia.com/advisories/36310"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://secunia.com/advisories/42896"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://security.gentoo.org/glsa/glsa-201101-05.xml"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21396389"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www-1.ibm.com/support/docview.wss?uid=swg1ID71123"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.debian.org/security/2009/dsa-1768"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:099"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.openafs.org/security/OPENAFS-SA-2009-002.txt"
    },
    {
      "source": "cve@mitre.org",
      "tags": [
        "Exploit"
      ],
      "url": "http://www.openafs.org/security/openafs-sa-2009-002.patch"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.securityfocus.com/bid/34404"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.vupen.com/english/advisories/2009/0984"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.vupen.com/english/advisories/2011/0117"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://secunia.com/advisories/34655"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://secunia.com/advisories/34684"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://secunia.com/advisories/36310"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://secunia.com/advisories/42896"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://security.gentoo.org/glsa/glsa-201101-05.xml"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21396389"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www-1.ibm.com/support/docview.wss?uid=swg1ID71123"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.debian.org/security/2009/dsa-1768"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:099"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.openafs.org/security/OPENAFS-SA-2009-002.txt"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Exploit"
      ],
      "url": "http://www.openafs.org/security/openafs-sa-2009-002.patch"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.securityfocus.com/bid/34404"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.vupen.com/english/advisories/2009/0984"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.vupen.com/english/advisories/2011/0117"
    }
  ],
  "sourceIdentifier": "cve@mitre.org",
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-189"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}

CVE-2009-1250 (GCVE-0-2009-1250)
Vulnerability from cvelistv5
Published
2009-04-09 00:00
Modified
2024-08-07 05:04
Severity ?
CWE
  • n/a
Summary
The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.
References
http://www.vupen.com/english/advisories/2011/0117 vdb-entry, x_refsource_VUPEN
http://www.openafs.org/security/openafs-sa-2009-002.patch x_refsource_CONFIRM
http://www.openafs.org/security/OPENAFS-SA-2009-002.txt x_refsource_CONFIRM
http://www.vupen.com/english/advisories/2009/0984 vdb-entry, x_refsource_VUPEN
http://www.mandriva.com/security/advisories?name=MDVSA-2009:099 vendor-advisory, x_refsource_MANDRIVA
http://www.securityfocus.com/bid/34404 vdb-entry, x_refsource_BID
http://secunia.com/advisories/36310 third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/34655 third-party-advisory, x_refsource_SECUNIA
http://www.debian.org/security/2009/dsa-1768 vendor-advisory, x_refsource_DEBIAN
http://www-1.ibm.com/support/docview.wss?uid=swg1ID71123 vendor-advisory, x_refsource_AIXAPAR
http://www-01.ibm.com/support/docview.wss?uid=swg21396389 x_refsource_CONFIRM
http://security.gentoo.org/glsa/glsa-201101-05.xml vendor-advisory, x_refsource_GENTOO
http://secunia.com/advisories/34684 third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/42896 third-party-advisory, x_refsource_SECUNIA
Impacted products
Vendor Product Version
n/a n/a Version: n/a
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-07T05:04:49.436Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "name": "ADV-2011-0117",
            "tags": [
              "vdb-entry",
              "x_refsource_VUPEN",
              "x_transferred"
            ],
            "url": "http://www.vupen.com/english/advisories/2011/0117"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "http://www.openafs.org/security/openafs-sa-2009-002.patch"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "http://www.openafs.org/security/OPENAFS-SA-2009-002.txt"
          },
          {
            "name": "ADV-2009-0984",
            "tags": [
              "vdb-entry",
              "x_refsource_VUPEN",
              "x_transferred"
            ],
            "url": "http://www.vupen.com/english/advisories/2009/0984"
          },
          {
            "name": "MDVSA-2009:099",
            "tags": [
              "vendor-advisory",
              "x_refsource_MANDRIVA",
              "x_transferred"
            ],
            "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:099"
          },
          {
            "name": "34404",
            "tags": [
              "vdb-entry",
              "x_refsource_BID",
              "x_transferred"
            ],
            "url": "http://www.securityfocus.com/bid/34404"
          },
          {
            "name": "36310",
            "tags": [
              "third-party-advisory",
              "x_refsource_SECUNIA",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/36310"
          },
          {
            "name": "34655",
            "tags": [
              "third-party-advisory",
              "x_refsource_SECUNIA",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/34655"
          },
          {
            "name": "DSA-1768",
            "tags": [
              "vendor-advisory",
              "x_refsource_DEBIAN",
              "x_transferred"
            ],
            "url": "http://www.debian.org/security/2009/dsa-1768"
          },
          {
            "name": "ID71123",
            "tags": [
              "vendor-advisory",
              "x_refsource_AIXAPAR",
              "x_transferred"
            ],
            "url": "http://www-1.ibm.com/support/docview.wss?uid=swg1ID71123"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21396389"
          },
          {
            "name": "GLSA-201101-05",
            "tags": [
              "vendor-advisory",
              "x_refsource_GENTOO",
              "x_transferred"
            ],
            "url": "http://security.gentoo.org/glsa/glsa-201101-05.xml"
          },
          {
            "name": "34684",
            "tags": [
              "third-party-advisory",
              "x_refsource_SECUNIA",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/34684"
          },
          {
            "name": "42896",
            "tags": [
              "third-party-advisory",
              "x_refsource_SECUNIA",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/42896"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "n/a",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ],
      "datePublic": "2009-04-06T00:00:00",
      "descriptions": [
        {
          "lang": "en",
          "value": "The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "n/a",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2009-04-16T09:00:00",
        "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "shortName": "mitre"
      },
      "references": [
        {
          "name": "ADV-2011-0117",
          "tags": [
            "vdb-entry",
            "x_refsource_VUPEN"
          ],
          "url": "http://www.vupen.com/english/advisories/2011/0117"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "http://www.openafs.org/security/openafs-sa-2009-002.patch"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "http://www.openafs.org/security/OPENAFS-SA-2009-002.txt"
        },
        {
          "name": "ADV-2009-0984",
          "tags": [
            "vdb-entry",
            "x_refsource_VUPEN"
          ],
          "url": "http://www.vupen.com/english/advisories/2009/0984"
        },
        {
          "name": "MDVSA-2009:099",
          "tags": [
            "vendor-advisory",
            "x_refsource_MANDRIVA"
          ],
          "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:099"
        },
        {
          "name": "34404",
          "tags": [
            "vdb-entry",
            "x_refsource_BID"
          ],
          "url": "http://www.securityfocus.com/bid/34404"
        },
        {
          "name": "36310",
          "tags": [
            "third-party-advisory",
            "x_refsource_SECUNIA"
          ],
          "url": "http://secunia.com/advisories/36310"
        },
        {
          "name": "34655",
          "tags": [
            "third-party-advisory",
            "x_refsource_SECUNIA"
          ],
          "url": "http://secunia.com/advisories/34655"
        },
        {
          "name": "DSA-1768",
          "tags": [
            "vendor-advisory",
            "x_refsource_DEBIAN"
          ],
          "url": "http://www.debian.org/security/2009/dsa-1768"
        },
        {
          "name": "ID71123",
          "tags": [
            "vendor-advisory",
            "x_refsource_AIXAPAR"
          ],
          "url": "http://www-1.ibm.com/support/docview.wss?uid=swg1ID71123"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21396389"
        },
        {
          "name": "GLSA-201101-05",
          "tags": [
            "vendor-advisory",
            "x_refsource_GENTOO"
          ],
          "url": "http://security.gentoo.org/glsa/glsa-201101-05.xml"
        },
        {
          "name": "34684",
          "tags": [
            "third-party-advisory",
            "x_refsource_SECUNIA"
          ],
          "url": "http://secunia.com/advisories/34684"
        },
        {
          "name": "42896",
          "tags": [
            "third-party-advisory",
            "x_refsource_SECUNIA"
          ],
          "url": "http://secunia.com/advisories/42896"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "cve@mitre.org",
          "ID": "CVE-2009-1250",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "n/a",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "n/a"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "n/a"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "n/a"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "ADV-2011-0117",
              "refsource": "VUPEN",
              "url": "http://www.vupen.com/english/advisories/2011/0117"
            },
            {
              "name": "http://www.openafs.org/security/openafs-sa-2009-002.patch",
              "refsource": "CONFIRM",
              "url": "http://www.openafs.org/security/openafs-sa-2009-002.patch"
            },
            {
              "name": "http://www.openafs.org/security/OPENAFS-SA-2009-002.txt",
              "refsource": "CONFIRM",
              "url": "http://www.openafs.org/security/OPENAFS-SA-2009-002.txt"
            },
            {
              "name": "ADV-2009-0984",
              "refsource": "VUPEN",
              "url": "http://www.vupen.com/english/advisories/2009/0984"
            },
            {
              "name": "MDVSA-2009:099",
              "refsource": "MANDRIVA",
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:099"
            },
            {
              "name": "34404",
              "refsource": "BID",
              "url": "http://www.securityfocus.com/bid/34404"
            },
            {
              "name": "36310",
              "refsource": "SECUNIA",
              "url": "http://secunia.com/advisories/36310"
            },
            {
              "name": "34655",
              "refsource": "SECUNIA",
              "url": "http://secunia.com/advisories/34655"
            },
            {
              "name": "DSA-1768",
              "refsource": "DEBIAN",
              "url": "http://www.debian.org/security/2009/dsa-1768"
            },
            {
              "name": "ID71123",
              "refsource": "AIXAPAR",
              "url": "http://www-1.ibm.com/support/docview.wss?uid=swg1ID71123"
            },
            {
              "name": "http://www-01.ibm.com/support/docview.wss?uid=swg21396389",
              "refsource": "CONFIRM",
              "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21396389"
            },
            {
              "name": "GLSA-201101-05",
              "refsource": "GENTOO",
              "url": "http://security.gentoo.org/glsa/glsa-201101-05.xml"
            },
            {
              "name": "34684",
              "refsource": "SECUNIA",
              "url": "http://secunia.com/advisories/34684"
            },
            {
              "name": "42896",
              "refsource": "SECUNIA",
              "url": "http://secunia.com/advisories/42896"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
    "assignerShortName": "mitre",
    "cveId": "CVE-2009-1250",
    "datePublished": "2009-04-09T00:00:00",
    "dateReserved": "2009-04-06T00:00:00",
    "dateUpdated": "2024-08-07T05:04:49.436Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}