CVE-2015-6587

Publication date 2 September 2015

Last updated 24 July 2024


Ubuntu priority

The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.

Read the notes from the security team

Status

Package Ubuntu Release Status
openafs 15.10 wily
Not affected
15.04 vivid Ignored end of life
14.04 LTS trusty
Fixed 1.6.7-1ubuntu1.1
12.04 LTS precise
Fixed 1.6.1-1+ubuntu0.6

Notes


mdeslaur

dupe of CVE-2015-3287