CVE-2016-9772: Infoleak
Published Feb 6, 2017
·Updated
OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2) fileserver vice partition, or (3) certain RPC responses.
Affected Software
1 affected component
OpenAFS OpenAFS<=1.6.19
Remediation
Patch Available
Event History
Feb 6, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9772?
CVE-2016-9772 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2016-9772?
To fix CVE-2016-9772, upgrade OpenAFS to version 1.6.20 or later.
3
What type of attack does CVE-2016-9772 facilitate?
CVE-2016-9772 allows remote attackers to obtain sensitive directory information.
4
Which versions of OpenAFS are affected by CVE-2016-9772?
OpenAFS versions 1.6.19 and earlier are affected by CVE-2016-9772.
5
What components are involved in CVE-2016-9772 vulnerabilities?
CVE-2016-9772 involves the client cache partition, fileserver vice partition, and certain RPC responses.