CVE-2019-18601: High severity npm vulnerability
Published Oct 29, 2019
·Updated
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series of VOTEDebug RPC calls to crash a database server within the SVOTEDebug RPC handler.
Affected Software
2 affected components
OpenAFS OpenAFS<1.6.24
OpenAFS OpenAFS>=1.8.0<1.8.5
Event History
Oct 29, 2019
CVE Published
via MITRE·01:40 PM
Data Sourced
via MITRE·01:40 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-18601?
CVE-2019-18601 has a severity rating that indicates it can lead to a denial of service attack.
2
How do I fix CVE-2019-18601?
To fix CVE-2019-18601, upgrade to OpenAFS version 1.6.24 or 1.8.5 or later.
3
What systems are affected by CVE-2019-18601?
CVE-2019-18601 affects OpenAFS versions prior to 1.6.24 and versions from 1.8.0 to 1.8.4 inclusive.
4
Can CVE-2019-18601 be exploited remotely?
Yes, CVE-2019-18601 can be exploited remotely by attackers making VOTE_Debug RPC calls.
5
What is the impact of CVE-2019-18601 on database servers?
CVE-2019-18601 can cause database servers to crash due to unserialized data access.