CVE-2014-0159: Buffer Overflow
Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial of service (crash) via a crafted statsVersion argument.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenAFSto a version that resolves this vulnerability.Fixed in 1.6.7 - Compensating control
Mitigate by preventing remote attackers from invoking the affected GetStatistics64 RPC (e.g., restrict network/RPC access so only trusted clients can reach the OpenAFS RPC endpoint).
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0159?
CVE-2014-0159 is classified as a high severity vulnerability that can result in denial of service.
How do I fix CVE-2014-0159?
To fix CVE-2014-0159, you should upgrade OpenAFS to version 1.6.7 or later.
What versions of OpenAFS are affected by CVE-2014-0159?
CVE-2014-0159 affects OpenAFS versions 1.4.8 through 1.6.6.
Can CVE-2014-0159 be exploited remotely?
Yes, CVE-2014-0159 can be exploited remotely by sending a crafted statsVersion argument.
What type of attack does CVE-2014-0159 facilitate?
CVE-2014-0159 facilitates a denial of service attack, leading to potential crashes in the affected software.