[Bug 1013374] New: VUL-1: CVE-2016-9772: OpenAFS: directory information leaks [OPENAFS-SA-2016-003]
![](https://seccdn.libravatar.org/avatar/3035b38ff33cf86f480bb169b8500b80.jpg?s=120&d=mm&r=g)
http://bugzilla.suse.com/show_bug.cgi?id=1013374 Bug ID: 1013374 Summary: VUL-1: CVE-2016-9772: OpenAFS: directory information leaks [OPENAFS-SA-2016-003] Classification: openSUSE Product: openSUSE Distribution Version: Leap 42.2 Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: mikhail.kasimov@gmail.com QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- Created attachment 704679 --> http://bugzilla.suse.com/attachment.cgi?id=704679&action=edit openAFS Security Advisor 2016-003 Reference: [1] http://seclists.org/oss-sec/2016/q4/558 [1]: ==================================================================== Hi The OpenAFS project has released a security advisory: https://www.openafs.org/pages/security/OPENAFS-SA-2016-003.txt OpenAFS Security Advisory 2016-003 Topic: directory information leakage Issued: 30 November, 2016 Affected: OpenAFS client versions 1.0 through 1.6.19 OpenAFS servers versions 1.0 through 1.6.19 The contents of OpenAFS directories may be leaked in client cache partitions, in fileserver vice partitions, and on the wire for certain RPCs. SUMMARY ======= Due to incomplete initialization or clearing of reused memory, OpenAFS directory objects are likely to contain "dead" directory entry information. This extraneous information is not active - that is, it is logically invisible to the fileserver and client. However, the leaked information is physically visible on the fileserver vice partition, on the wire in FetchData replies and other RPCs, and on the client cache partition. This constitutes a leak of directory information. I'm attaching the full advisory for reference (and to have it int the list archives). Patches: https://www.openafs.org/pages/security/openafs-sa-2016-003.patch https://www.openafs.org/pages/security/openafs-sa-2016-003-master.patch Could you please assign a CVE for the directory information leak issue in OpenAFS? Regards, Salvatore Attachment: OPENAFS-SA-2016-003.txt Description: ==================================================================== [2] https://software.opensuse.org/package/openafs (1.6.20 in filesystem repo for all basline (open-)SUSE versions. Needs to be checked.) -- You are receiving this mail because: You are on the CC list for the bug.
![](https://seccdn.libravatar.org/avatar/3035b38ff33cf86f480bb169b8500b80.jpg?s=120&d=mm&r=g)
http://bugzilla.suse.com/show_bug.cgi?id=1013374
Mikhail Kasimov
![](https://seccdn.libravatar.org/avatar/3035b38ff33cf86f480bb169b8500b80.jpg?s=120&d=mm&r=g)
http://bugzilla.suse.com/show_bug.cgi?id=1013374
http://bugzilla.suse.com/show_bug.cgi?id=1013374#c1
Swamp Workflow Management
![](https://seccdn.libravatar.org/avatar/3035b38ff33cf86f480bb169b8500b80.jpg?s=120&d=mm&r=g)
http://bugzilla.suse.com/show_bug.cgi?id=1013374
http://bugzilla.suse.com/show_bug.cgi?id=1013374#c2
Marcus Meissner
![](https://seccdn.libravatar.org/avatar/3035b38ff33cf86f480bb169b8500b80.jpg?s=120&d=mm&r=g)
http://bugzilla.suse.com/show_bug.cgi?id=1013374
http://bugzilla.suse.com/show_bug.cgi?id=1013374#c3
Christof Hanke
participants (1)
-
bugzilla_noreply@novell.com