CVE-2013-4135: Medium severity OpenAFS OpenAFS vulnerability
The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrity protection and sends data in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4135?
CVE-2013-4135 is rated as a medium severity vulnerability due to the risk of sensitive information being exposed.
How do I fix CVE-2013-4135?
To mitigate CVE-2013-4135, upgrade OpenAFS to version 1.6.5 or later where the vulnerability has been addressed.
What systems are affected by CVE-2013-4135?
CVE-2013-4135 affects OpenAFS versions 1.6.0 through 1.6.4 as well as Debian Linux 7.0 using these OpenAFS versions.
What type of attack does CVE-2013-4135 allow?
CVE-2013-4135 allows remote attackers to sniff network traffic and obtain sensitive information due to the use of cleartext data transmission.
Is there a workaround for CVE-2013-4135?
There is no recommended workaround for CVE-2013-4135; the best course of action is to upgrade to a secure version of OpenAFS.