Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.69001
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2168-1)
Summary:The remote host is missing an update for the Debian 'openafs' package(s) announced via the DSA-2168-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'openafs' package(s) announced via the DSA-2168-1 advisory.

Vulnerability Insight:
Two vulnerabilities were discovered the distributed filesystem AFS:

CVE-2011-0430

Andrew Deason discovered that a double free in the Rx server process could lead to denial of service or the execution of arbitrary code.

CVE-2011-0431

It was discovered that insufficient error handling in the kernel module could lead to denial of service.

For the oldstable distribution (lenny), this problem has been fixed in version 1.4.7.dfsg1-6+lenny4. Due to a technical problem with the buildd infrastructure the update is not yet available, but will be installed into the archive soon.

For the stable distribution (squeeze), this problem has been fixed in version 1.4.12.1+dfsg-4.

For the unstable distribution (sid), this problem has been fixed in version 1.4.14+dfsg-1.

We recommend that you upgrade your openafs packages. Note that in order to apply this security update, you must rebuild the OpenAFS kernel module.

Affected Software/OS:
'openafs' package(s) on Debian 5, Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-0430
BugTraq ID: 46428
http://www.securityfocus.com/bid/46428
Debian Security Information: DSA-2168 (Google Search)
http://www.debian.org/security/2011/dsa-2168
http://www.securitytracker.com/id?1025095
http://secunia.com/advisories/43371
http://secunia.com/advisories/43407
http://www.vupen.com/english/advisories/2011/0410
http://www.vupen.com/english/advisories/2011/0411
Common Vulnerability Exposure (CVE) ID: CVE-2011-0431
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.