CVE-2015-3282
published 2015-08-12CVE-2015-3282: vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network.
PriorityP426medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.88%
77.2th percentile
vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openafs | < openafs 1.6.13-1 (bookworm) | openafs 1.6.13-1 (bookworm) |
| openafs | openafs | <= 1.6.12 | — |
| openafs | openafs | >= 0 < 1.6.13-1 | 1.6.13-1 |
| openafs | openafs | >= 0 < 1.6.13-1 | 1.6.13-1 |
| openafs | openafs | >= 0 < 1.6.13-1 | 1.6.13-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2j3g-mmqf-22pf: vos in OpenAFS before 1
ghsa_unreviewed·2022-05-17
CVE-2015-3282 [MEDIUM] CWE-200 GHSA-2j3g-mmqf-22pf: vos in OpenAFS before 1
vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network.
OSV
CVE-2015-3282: vos in OpenAFS before 1
osv·2015-08-12·CVSS 4.3
CVE-2015-3282 [MEDIUM] CVE-2015-3282: vos in OpenAFS before 1
vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network.
Debian
CVE-2015-3282: openafs - vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attacker...
vendor_debian·2015·CVSS 4.3
CVE-2015-3282 [MEDIUM] CVE-2015-3282: openafs - vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attacker...
vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network.
Scope: local
bookworm: resolved (fixed in 1.6.13-1)
bullseye: resolved (fixed in 1.6.13-1)
sid: resolved (fixed in 1.6.13-1)
trixie: resolved (fixed in 1.6.13-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.debian.org/security/2015/dsa-3320http://www.openafs.org/pages/security/OPENAFS-SA-2015-001.txthttp://www.securitytracker.com/id/1033262https://lists.openafs.org/pipermail/openafs-announce/2015/000486.htmlhttps://www.openafs.org/dl/openafs/1.6.13/RELNOTES-1.6.13http://www.debian.org/security/2015/dsa-3320http://www.openafs.org/pages/security/OPENAFS-SA-2015-001.txthttp://www.securitytracker.com/id/1033262https://lists.openafs.org/pipermail/openafs-announce/2015/000486.htmlhttps://www.openafs.org/dl/openafs/1.6.13/RELNOTES-1.6.13
2015-08-12
Published