CVE-2016-2860: Medium severity npm vulnerability
The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by leveraging mishandling of the creator ID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2860?
CVE-2016-2860 is classified as a critical vulnerability due to its ability to allow unauthorized privilege escalation.
How do I fix CVE-2016-2860?
To fix CVE-2016-2860, upgrade OpenAFS to version 1.6.17 or later.
Who is affected by CVE-2016-2860?
CVE-2016-2860 affects remote authenticated users from foreign Kerberos realms using OpenAFS versions prior to 1.6.17.
What impact does CVE-2016-2860 have?
CVE-2016-2860 allows attackers to bypass access restrictions and create arbitrary groups, potentially compromising system security.
Is there a workaround for CVE-2016-2860?
There is no official workaround for CVE-2016-2860; the recommended action is to update to the latest version.