First published: Tue Oct 29 2019(Updated: )
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm | <1.6.24 | |
npm | >=1.8.0<1.8.5 | |
Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18603 is classified as a medium severity vulnerability due to its potential for information leakage.
To remediate CVE-2019-18603, upgrade OpenAFS to version 1.6.24 or 1.8.5 or later.
CVE-2019-18603 affects OpenAFS versions before 1.6.24 and 1.8.x versions before 1.8.5, as well as Debian Linux 8.0.
CVE-2019-18603 is an information leakage vulnerability that occurs under certain error conditions.
Yes, CVE-2019-18603 can lead to leakage of uninitialized RPC output variables over the network, which may expose sensitive information.