Bug ID 1013374
Summary VUL-1: CVE-2016-9772: OpenAFS: directory information leaks [OPENAFS-SA-2016-003]
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.2
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee security-team@suse.de
Reporter mikhail.kasimov@gmail.com
QA Contact qa-bugs@suse.de
Found By ---
Blocker ---

Created attachment 704679 [details]
openAFS Security Advisor 2016-003

Reference: [1] http://seclists.org/oss-sec/2016/q4/558

[1]:
====================================================================
Hi

The OpenAFS project has released a security advisory:

https://www.openafs.org/pages/security/OPENAFS-SA-2016-003.txt

OpenAFS Security Advisory 2016-003

    Topic: directory information leakage

    Issued: 30 November, 2016
    Affected: OpenAFS client versions 1.0 through 1.6.19
              OpenAFS servers versions 1.0 through 1.6.19

    The contents of OpenAFS directories may be leaked in client cache
partitions,
    in fileserver vice partitions, and on the wire for certain RPCs.

    SUMMARY
    =======

    Due to incomplete initialization or clearing of reused memory, OpenAFS
    directory objects are likely to contain "dead" directory entry information.
    This extraneous information is not active - that is, it is logically
invisible
    to the fileserver and client. However, the leaked information is physically
    visible on the fileserver vice partition, on the wire in FetchData replies
and
    other RPCs, and on the client cache partition. This constitutes a leak of
    directory information.


I'm attaching the full advisory for reference (and to have it int the
list archives).

Patches:

https://www.openafs.org/pages/security/openafs-sa-2016-003.patch
https://www.openafs.org/pages/security/openafs-sa-2016-003-master.patch

Could you please assign a CVE for the directory information leak issue
in OpenAFS?

Regards,
Salvatore

Attachment: OPENAFS-SA-2016-003.txt
Description:
====================================================================

[2] https://software.opensuse.org/package/openafs (1.6.20 in filesystem repo
for all basline (open-)SUSE versions. Needs to be checked.)


You are receiving this mail because: