First published: Tue Oct 29 2019(Updated: )
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm | <1.6.24 | |
npm | >=1.8.0<1.8.5 | |
Debian | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18602 has been classified as an information disclosure vulnerability.
To resolve CVE-2019-18602, update OpenAFS to version 1.6.24 or 1.8.5 or later.
OpenAFS versions before 1.6.24 and any version in the 1.8.x series prior to 1.8.5 are affected by CVE-2019-18602.
CVE-2019-18602 is an information disclosure vulnerability caused by uninitialized scalars being sent over the network.
Yes, Debian Linux version 8.0 is affected by CVE-2019-18602 if it uses vulnerable OpenAFS versions.