CVE-2014-2852: Input Validation
Published Apr 14, 2014
·Updated
OpenAFS before 1.6.7 delays the listen thread when an RXSCheckResponse fails, which allows remote attackers to cause a denial of service (performance degradation) via an invalid packet.
Affected Software
10 affected components
OpenAFS OpenAFS<=1.6.6
OpenAFS OpenAFS=1.6.0
OpenAFS OpenAFS=1.6.1
OpenAFS OpenAFS=1.6.2
OpenAFS OpenAFS=1.6.2.1
OpenAFS OpenAFS=1.6.3
OpenAFS OpenAFS=1.6.4
OpenAFS OpenAFS=1.6.5
OpenAFS OpenAFS=1.6.5.1
OpenAFS OpenAFS=1.6.5.2
Event History
Apr 14, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:09 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2852?
CVE-2014-2852 has a medium severity level due to its denial-of-service impact on OpenAFS.
2
How do I fix CVE-2014-2852?
To fix CVE-2014-2852, upgrade OpenAFS to version 1.6.7 or later.
3
What versions of OpenAFS are affected by CVE-2014-2852?
CVE-2014-2852 affects OpenAFS versions prior to 1.6.7, specifically from 1.6.0 to 1.6.6.
4
What type of vulnerability is CVE-2014-2852?
CVE-2014-2852 is a denial-of-service vulnerability caused by improper packet handling.
5
Can CVE-2014-2852 be exploited remotely?
Yes, CVE-2014-2852 can be exploited remotely, allowing attackers to degrade performance through invalid packets.