CVE-2014-2830: Buffer Overflow
Sebastian Krahmer discovered a stack-based buffer overflow flaw in cifskey.c, which is used by pamcifscreds.
A patch is available from the following: https://bugzilla.novell.com/showbug.cgi?id=870168
References: http://seclists.org/oss-sec/2014/q2/66
Other sources
Stack-based buffer overflow in cifskey.c or cifscreds.c in cifs-utils before 6.4, as used in pamcifscreds, allows remote attackers to have unspecified impact via unknown vectors.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2830?
CVE-2014-2830 is rated as high severity due to the potential for exploitation through stack-based buffer overflow.
How do I fix CVE-2014-2830?
To fix CVE-2014-2830, you should update the cifs-utils package to the latest patched version.
Which versions of cifs-utils are affected by CVE-2014-2830?
CVE-2014-2830 affects cifs-utils versions up to and including 6.3.
What is the nature of the vulnerability in CVE-2014-2830?
CVE-2014-2830 is a stack-based buffer overflow vulnerability in the cifskey.c file used by pam_cifscreds.
Who discovered CVE-2014-2830?
CVE-2014-2830 was discovered by Sebastian Krahmer.