CVE Vulnerabilities

CVE-2013-4135

Published: Nov 05, 2013 | Modified: Aug 24, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrity protection and sends data in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

Affected Software

Name Vendor Start Version End Version
Openafs Openafs 1.6.0 (including) 1.6.0 (including)
Openafs Openafs 1.6.1 (including) 1.6.1 (including)
Openafs Openafs 1.6.2 (including) 1.6.2 (including)
Openafs Openafs 1.6.2.1 (including) 1.6.2.1 (including)
Openafs Openafs 1.6.3 (including) 1.6.3 (including)
Openafs Openafs 1.6.4 (including) 1.6.4 (including)
Openafs Ubuntu devel *
Openafs Ubuntu lucid *
Openafs Ubuntu precise *
Openafs Ubuntu quantal *
Openafs Ubuntu raring *
Openafs Ubuntu upstream *

References