CVE-2019-18603

MEDIUM

OpenAFS <1.6.24, <1.8.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/11/msg00002.html

Scores

CVSS v3 5.9
EPSS 0.0121
EPSS Percentile 64.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-908
Status published
Products (2)
debian/debian_linux 8.0
openafs/openafs < 1.6.24
Published Oct 29, 2019
Tracked Since Feb 18, 2026