CVE-2009-1250

The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
ibmafs
𝑥
≤ 3.6
ibmafs
3.6
ibmafs
3.6:patch12
ibmafs
3.6:patch13
ibmafs
3.6:patch14
ibmafs
3.6:patch15
ibmafs
3.6:patch16
openafsopenafs
1.0
openafsopenafs
1.0.1
openafsopenafs
1.0.2
openafsopenafs
1.0.3
openafsopenafs
1.0.4
openafsopenafs
1.0.4a:a
openafsopenafs
1.1
openafsopenafs
1.1.0
openafsopenafs
1.1.1
openafsopenafs
1.1.1a:a
openafsopenafs
1.2
openafsopenafs
1.2.1
openafsopenafs
1.2.2
openafsopenafs
1.2.2a:a
openafsopenafs
1.2.2b:b
openafsopenafs
1.2.3
openafsopenafs
1.2.4
openafsopenafs
1.2.5
openafsopenafs
1.2.6
openafsopenafs
1.2.7
openafsopenafs
1.2.8
openafsopenafs
1.2.9
openafsopenafs
1.2.10
openafsopenafs
1.2.11
openafsopenafs
1.2.13
openafsopenafs
1.3
openafsopenafs
1.3.1
openafsopenafs
1.3.2
openafsopenafs
1.3.5
openafsopenafs
1.3.70
openafsopenafs
1.3.74
openafsopenafs
1.3.77
openafsopenafs
1.3.81
openafsopenafs
1.4
openafsopenafs
1.4.0
openafsopenafs
1.4.3
openafsopenafs
1.4.4
openafsopenafs
1.4.5
openafsopenafs
1.4.6
openafsopenafs
1.4.7
openafsopenafs
1.4.7_pre1:_pre1
openafsopenafs
1.4.7_pre2:_pre2
openafsopenafs
1.4.7_pre3:_pre3
openafsopenafs
1.4.7_pre4:_pre4
openafsopenafs
1.4.7_pre5:_pre5
openafsopenafs
1.4.8
openafsopenafs
1.4.8_pre1:_pre1
openafsopenafs
1.4.8_pre2:_pre2
openafsopenafs
1.4.8_pre3:_pre3
openafsopenafs
1.5
openafsopenafs
1.5.16
openafsopenafs
1.5.17
openafsopenafs
1.5.26
openafsopenafs
1.5.27
openafsopenafs
1.5.30
openafsopenafs
1.5.31
openafsopenafs
1.5.32
openafsopenafs
1.5.33
openafsopenafs
1.5.34
openafsopenafs
1.5.35
openafsopenafs
1.5.36
openafsopenafs
1.5.38
openafsopenafs
1.5.39
openafsopenafs
1.5.50
openafsopenafs
1.5.52
openafsopenafs
1.5.53
openafsopenafs
1.5.54
openafsopenafs
1.5.55
openafsopenafs
1.5.56
openafsopenafs
1.5.57
openafsopenafs
1.5.58
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openafs
bullseye
1.8.6-5
fixed
bookworm
1.8.9-1
fixed
sid
1.8.12.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openafs
intrepid
Fixed 1.4.7.dfsg1-6+ubuntu0.1
released
hardy
Fixed 1.4.6.dfsg1-2+ubuntu0.1
released
gutsy
ignored
dapper
Fixed 1.4.1-2+ubuntu0.1
released
Common Weakness Enumeration