CVE-2011-0430
Published: 19 February 2011
Double free vulnerability in the Rx server process in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions allows remote attackers to cause a denial of service and execute arbitrary code via unknown vectors.
Priority
Status
Package | Release | Status |
---|---|---|
openafs Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Ignored
(end of life)
|
|
karmic |
Ignored
(end of life)
|
|
lucid |
Released
(1.4.12+dfsg-3+ubuntu0.1)
|
|
maverick |
Ignored
(end of life)
|
|
natty |
Not vulnerable
(1.4.14+dfsg-1+ubuntu1)
|
|
oneiric |
Not vulnerable
(1.4.14+dfsg-1+ubuntu1)
|
|
upstream |
Released
(1.4.14)
|
|
Patches: upstream: http://www.openafs.org/pages/security/rxkad-asn1-null-free.patch debdiff: https://bugs.launchpad.net/ubuntu/natty/+source/openafs/+bug/723121 |