First published: Tue Oct 29 2019(Updated: )
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to crash a database server within the SVOTE_Debug RPC handler.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm | <1.6.24 | |
npm | >=1.8.0<1.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18601 has a severity rating that indicates it can lead to a denial of service attack.
To fix CVE-2019-18601, upgrade to OpenAFS version 1.6.24 or 1.8.5 or later.
CVE-2019-18601 affects OpenAFS versions prior to 1.6.24 and versions from 1.8.0 to 1.8.4 inclusive.
Yes, CVE-2019-18601 can be exploited remotely by attackers making VOTE_Debug RPC calls.
CVE-2019-18601 can cause database servers to crash due to unserialized data access.