First published: Mon Apr 14 2014(Updated: )
Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial of service (crash) via a crafted statsVersion argument.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm | =1.4.8 | |
npm | =1.4.9 | |
npm | =1.4.10 | |
npm | =1.4.11 | |
npm | =1.4.12 | |
npm | =1.4.14 | |
npm | =1.4.14.1 | |
npm | =1.4.15 | |
npm | =1.6.0 | |
npm | =1.6.1 | |
npm | =1.6.2 | |
npm | =1.6.2.1 | |
npm | =1.6.3 | |
npm | =1.6.4 | |
npm | =1.6.5 | |
npm | =1.6.5.1 | |
npm | =1.6.5.2 | |
npm | =1.6.6 | |
Debian Linux | =7.0 | |
=1.4.8 | ||
=1.4.9 | ||
=1.4.10 | ||
=1.4.11 | ||
=1.4.12 | ||
=1.4.14 | ||
=1.4.14.1 | ||
=1.4.15 | ||
=1.6.0 | ||
=1.6.1 | ||
=1.6.2 | ||
=1.6.2.1 | ||
=1.6.3 | ||
=1.6.4 | ||
=1.6.5 | ||
=1.6.5.1 | ||
=1.6.5.2 | ||
=1.6.6 | ||
=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0159 is classified as a high severity vulnerability that can result in denial of service.
To fix CVE-2014-0159, you should upgrade OpenAFS to version 1.6.7 or later.
CVE-2014-0159 affects OpenAFS versions 1.4.8 through 1.6.6.
Yes, CVE-2014-0159 can be exploited remotely by sending a crafted statsVersion argument.
CVE-2014-0159 facilitates a denial of service attack, leading to potential crashes in the affected software.