VulnerabilityModified
CVE-2019-18603
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer.
MEDIUM 5.9EPSS 1.21%
Does this matter?
Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.
Description
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-908
- Affected
- openafs/openafs · debian/debian linux
- Source
- cve@mitre.org
References
- https://lists.debian.org/debian-lts-announce/2019/11/msg00002.htmlMailing List, Third Party Advisory
- https://openafs.org/pages/security/OPENAFS-SA-2019-001.txtVendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/11/msg00002.htmlMailing List, Third Party Advisory
- https://openafs.org/pages/security/OPENAFS-SA-2019-001.txtVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.