CVE-2009-1251: Buffer Overflow
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via an RX response containing more data than specified in a request, related to use of XDR arrays.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1251?
CVE-2009-1251 has a high severity rating as it allows remote attackers to potentially execute arbitrary code or cause a denial of service.
How do I fix CVE-2009-1251?
To fix CVE-2009-1251, upgrade OpenAFS to version 1.5.59 or later, which includes patches to address this vulnerability.
What software versions are affected by CVE-2009-1251?
CVE-2009-1251 affects OpenAFS versions 1.0 through 1.4.8 and versions 1.5.0 through 1.5.58 on Unix platforms.
Can CVE-2009-1251 lead to a system crash?
Yes, CVE-2009-1251 can cause a denial of service resulting in a system crash due to the buffer overflow in the cache manager.
What are the potential impacts of exploiting CVE-2009-1251?
Exploiting CVE-2009-1251 can lead to remote code execution and denial of service, compromising the security and stability of affected systems.