CVE-2019-18602: High severity npm vulnerability
Published Oct 29, 2019
·Updated
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer.
Affected Software
3 affected components
OpenAFS OpenAFS<1.6.24
OpenAFS OpenAFS>=1.8.0<1.8.5
Debian Debian Linux=8.0
Event History
Oct 29, 2019
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-18602?
CVE-2019-18602 has been classified as an information disclosure vulnerability.
2
How do I fix CVE-2019-18602?
To resolve CVE-2019-18602, update OpenAFS to version 1.6.24 or 1.8.5 or later.
3
Which versions of OpenAFS are affected by CVE-2019-18602?
OpenAFS versions before 1.6.24 and any version in the 1.8.x series prior to 1.8.5 are affected by CVE-2019-18602.
4
What type of vulnerability is CVE-2019-18602?
CVE-2019-18602 is an information disclosure vulnerability caused by uninitialized scalars being sent over the network.
5
Is Debian Linux affected by CVE-2019-18602?
Yes, Debian Linux version 8.0 is affected by CVE-2019-18602 if it uses vulnerable OpenAFS versions.