CVE Vulnerabilities

CVE-2019-18602

Use of Uninitialized Resource

Published: Oct 29, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

NameVendorStart VersionEnd Version
OpenafsOpenafs*1.6.24 (excluding)
OpenafsOpenafs1.8.0 (including)1.8.5 (excluding)
OpenafsUbuntubionic*
OpenafsUbuntudisco*
OpenafsUbuntueoan*
OpenafsUbuntuesm-apps/bionic*
OpenafsUbuntuesm-apps/focal*
OpenafsUbuntuesm-apps/jammy*
OpenafsUbuntuesm-apps/xenial*
OpenafsUbuntufocal*
OpenafsUbuntugroovy*
OpenafsUbuntuhirsute*
OpenafsUbuntuimpish*
OpenafsUbuntujammy*
OpenafsUbuntukinetic*
OpenafsUbuntutrusty*
OpenafsUbuntuupstream*
OpenafsUbuntuxenial*

Potential Mitigations

References