CVE-2015-3282: Infoleak
Published Aug 12, 2015
·Updated
vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network.
Affected Software
1 affected component
OpenAFS OpenAFS<=1.6.12
Event History
Aug 12, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3282?
CVE-2015-3282 has been classified as a medium severity vulnerability due to its potential impact on data confidentiality.
2
How do I fix CVE-2015-3282?
The recommended fix for CVE-2015-3282 is to upgrade OpenAFS to version 1.6.13 or later to mitigate the vulnerability.
3
Who is affected by CVE-2015-3282?
CVE-2015-3282 affects users of OpenAFS versions prior to 1.6.13, particularly those who utilize VLDB entries.
4
What kind of attack does CVE-2015-3282 enable?
CVE-2015-3282 allows remote attackers to obtain sensitive stack data by sniffing the network traffic.
5
Is CVE-2015-3282 still a risk if I have version 1.6.12 of OpenAFS?
Yes, if you are using version 1.6.12 or earlier of OpenAFS, you are at risk from CVE-2015-3282 and should upgrade immediately.