CVE-2015-6587: Buffer Overflow
Published Sep 2, 2015
·Updated
The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VLListAttributesN2 RPC.
Affected Software
3 affected components
OpenAFS OpenAFS<=1.6.12
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Event History
Sep 2, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6587?
CVE-2015-6587 has been classified as a high severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2015-6587?
To fix CVE-2015-6587, you should upgrade to OpenAFS version 1.6.13 or later.
3
Who is affected by CVE-2015-6587?
CVE-2015-6587 affects remote authenticated users of OpenAFS versions before 1.6.13.
4
What impact does CVE-2015-6587 have?
The impact of CVE-2015-6587 can result in an out-of-bounds read and crash of the vlserver.
5
What versions of Debian are affected by CVE-2015-6587?
Debian Linux versions 7.0 and 8.0 are affected by CVE-2015-6587.