CVE-2015-7763: Infoleak
rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padding at the end of an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conducting a replay attack or (2) sniffing the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7763?
CVE-2015-7763 has been classified as moderate severity due to its potential to allow sensitive information disclosure through replay attacks or packet sniffing.
How do I fix CVE-2015-7763?
To resolve CVE-2015-7763, update OpenAFS to version 1.6.15 or later, or to 1.7.33 or later, which contains the required fixes.
Which versions of OpenAFS are affected by CVE-2015-7763?
CVE-2015-7763 affects OpenAFS versions 1.5.75 through 1.5.78, all 1.6.x versions prior to 1.6.15, and all 1.7.x versions prior to 1.7.33.
What are the potential impacts of CVE-2015-7763?
The primary impact of CVE-2015-7763 includes the risk of sensitive information leakage, which can occur during a network replay attack or through packet sniffing.
Are there any workarounds for CVE-2015-7763 until I can apply a fix?
Temporary workarounds for CVE-2015-7763 are limited, so applying the appropriate software update is strongly recommended to mitigate the vulnerability.