Bug ID | 1013374 |
---|---|
Summary | VUL-1: CVE-2016-9772: OpenAFS: directory information leaks [OPENAFS-SA-2016-003] |
Classification | openSUSE |
Product | openSUSE Distribution |
Version | Leap 42.2 |
Hardware | Other |
OS | Other |
Status | NEW |
Severity | Normal |
Priority | P5 - None |
Component | Security |
Assignee | security-team@suse.de |
Reporter | mikhail.kasimov@gmail.com |
QA Contact | qa-bugs@suse.de |
Found By | --- |
Blocker | --- |
Created attachment 704679 [details] openAFS Security Advisor 2016-003 Reference: [1] http://seclists.org/oss-sec/2016/q4/558 [1]: ==================================================================== Hi The OpenAFS project has released a security advisory: https://www.openafs.org/pages/security/OPENAFS-SA-2016-003.txt OpenAFS Security Advisory 2016-003 Topic: directory information leakage Issued: 30 November, 2016 Affected: OpenAFS client versions 1.0 through 1.6.19 OpenAFS servers versions 1.0 through 1.6.19 The contents of OpenAFS directories may be leaked in client cache partitions, in fileserver vice partitions, and on the wire for certain RPCs. SUMMARY ======= Due to incomplete initialization or clearing of reused memory, OpenAFS directory objects are likely to contain "dead" directory entry information. This extraneous information is not active - that is, it is logically invisible to the fileserver and client. However, the leaked information is physically visible on the fileserver vice partition, on the wire in FetchData replies and other RPCs, and on the client cache partition. This constitutes a leak of directory information. I'm attaching the full advisory for reference (and to have it int the list archives). Patches: https://www.openafs.org/pages/security/openafs-sa-2016-003.patch https://www.openafs.org/pages/security/openafs-sa-2016-003-master.patch Could you please assign a CVE for the directory information leak issue in OpenAFS? Regards, Salvatore Attachment: OPENAFS-SA-2016-003.txt Description: ==================================================================== [2] https://software.opensuse.org/package/openafs (1.6.20 in filesystem repo for all basline (open-)SUSE versions. Needs to be checked.)