Back to Database
Status published
Medium
CVE-2013-1794
Buffer overflow in certain client utilities in OpenAFS before 1.6.2...
Vulnerability Description
Buffer overflow in certain client utilities in OpenAFS before 1.6.2 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long fileserver ACL entry.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-1794
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.openafs.org/pages/security/OPENAFS-SA-2013-001.txt
- http://secunia.com/advisories/52480
- http://secunia.com/advisories/52342
- http://www.debian.org/security/2013/dsa-2638
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:244
- http://www.securityfocus.com/bid/58299
- https://exchange.xforce.ibmcloud.com/vulnerabilities/82582
More from openafs
View All →CVE-2019-18603
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to...
Medium
5.9
CVE-2019-18602
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to...
High
7.5
CVE-2019-18601
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to...
High
7.5
CVE-2018-16949
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x...
High
7.5
CVE-2018-16948
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x...
High
7.5
Affected Vendor
openafs
View all reports →Affected Software
openafs
Vulnerable Versions:
0, 1.5.10, 1.5.11, 1.5.12, 1.5.13, 1.5.14, 1.5.15, 1.5.16, 1.5.17, 1.5.18, 1.5.19, 1.5.20, 1.5.21, 1.5.22, 1.5.23, 1.5.24, 1.5.25, 1.5.26, 1.5.27, 1.5.28, 1.5.29, 1.5.30, 1.5.31, 1.5.32, 1.5.33, 1.5.34, 1.5.35, 1.5.36, 1.5.37, 1.5.38, 1.5.39, 1.5.50, 1.5.51, 1.5.52, 1.5.53, 1.5.54, 1.5.55, 1.5.56, 1.5.57, 1.5.58, 1.5.59, 1.5.60, 1.5.61, 1.5.62, 1.5.63, 1.5.64, 1.5.65, 1.5.66, 1.5.67, 1.5.68, 1.5.69, 1.5.70, 1.5.71, 1.5.72, 1.5.73, 1.5.74, 1.5.75, 1.5.76, 1.5.77, 1.5.78, 1.6.0
Timeline
Official Publish:
March 12th, 2013
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.