CVE-2009-1250

OpenAFS 1.0-1.4.8 and 1.5.0-1.5.58 - Denial of Service via RX Response Error Code

Title source: llm
STIX 2.1

Description

The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.

References (14)

Core 14
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0117
Various Sources x_refsource_confirm
http://www.openafs.org/security/OPENAFS-SA-2009-002.txt
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0984
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:099
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34404
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36310
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34655
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1768
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1ID71123
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21396389
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201101-05.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34684
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42896

Scores

EPSS 0.0398
EPSS Percentile 89.4%

Details

CWE
CWE-189
Status published
Products (45)
ibm/afs 3.6 (6 CPE variants)
ibm/afs < 3.6
openafs/openafs 1.0
openafs/openafs 1.0.1
openafs/openafs 1.0.2
openafs/openafs 1.0.3
openafs/openafs 1.0.4
openafs/openafs 1.0.4a
openafs/openafs 1.1
openafs/openafs 1.1.0
... and 35 more
Published Apr 09, 2009
Tracked Since Feb 18, 2026