CVE Vulnerabilities

CVE-2019-18603

Use of Uninitialized Resource

Published: Oct 29, 2019 | Modified: Nov 21, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

NameVendorStart VersionEnd Version
OpenafsOpenafs*1.6.24 (excluding)
OpenafsOpenafs1.8.0 (including)1.8.5 (excluding)
OpenafsUbuntubionic*
OpenafsUbuntudisco*
OpenafsUbuntueoan*
OpenafsUbuntufocal*
OpenafsUbuntugroovy*
OpenafsUbuntuhirsute*
OpenafsUbuntuimpish*
OpenafsUbuntukinetic*
OpenafsUbuntutrusty*
OpenafsUbuntuupstream*
OpenafsUbuntuxenial*

Potential Mitigations

References