CVE-2013-4135

Publication date 5 November 2013

Last updated 24 July 2024


Ubuntu priority

Description

The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrity protection and sends data in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

Status

Package Ubuntu Release Status
openafs 13.04 raring
Fixed 1.6.2-1+ubuntu2.1
12.10 quantal
Fixed 1.6.1-2+ubuntu2.1
12.04 LTS precise
Fixed 1.6.1-1+ubuntu0.2
10.04 LTS lucid
Fixed 1.4.12+dfsg-3+ubuntu0.3


Access our resources on patching vulnerabilities