CVE-2015-6587
published 2015-09-02CVE-2015-6587: The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular…
PriorityP417medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
1.93%
77.9th percentile
The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openafs | < openafs 1.6.13-1 (bookworm) | openafs 1.6.13-1 (bookworm) |
| openafs | openafs | <= 1.6.12 | — |
| openafs | openafs | >= 0 < 1.6.13-1 | 1.6.13-1 |
| openafs | openafs | >= 0 < 1.6.13-1 | 1.6.13-1 |
| openafs | openafs | >= 0 < 1.6.13-1 | 1.6.13-1 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_debian4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-6587: openafs - The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause...
vendor_debian·2015·CVSS 4.0
CVE-2015-6587 [MEDIUM] CVE-2015-6587: openafs - The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause...
The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.
Scope: local
bookworm: resolved (fixed in 1.6.13-1)
bullseye: resolved (fixed in 1.6.13-1)
sid: resolved (fixed in 1.6.13-1)
trixie: resolved (fixed in 1.6.13-1)
GHSA
GHSA-2rmv-q4gp-w43q: The vlserver in OpenAFS before 1
ghsa_unreviewed·2022-05-17
CVE-2015-6587 [MEDIUM] CWE-119 GHSA-2rmv-q4gp-w43q: The vlserver in OpenAFS before 1
The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.
OSV
CVE-2015-6587: The vlserver in OpenAFS before 1
osv·2015-09-02·CVSS 4.0
CVE-2015-6587 [MEDIUM] CVE-2015-6587: The vlserver in OpenAFS before 1
The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.
OSV
openjdk-7 vulnerabilities
osv·2015-01-28·CVSS 3.4
CVE-2014-3566 openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-3566, CVE-2014-6587, CVE-2014-6601, CVE-2015-0395,
CVE-2015-0408, CVE-2015-0412)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data over the network. (CVE-2014-6585, CVE-2014-6591, CVE-2015-0400,
CVE-2015-0407)
A vulnerability was discovered in the OpenJDK JRE related to
information disclosure and integrity. An attacker could exploit this to
expose sensitive data over the network. (CVE-2014-6593)
A vulnerability was discovere
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.debian.org/security/2015/dsa-3320http://www.openafs.org/pages/security/OPENAFS-SA-2015-006.txthttps://lists.openafs.org/pipermail/openafs-announce/2015/000486.htmlhttps://www.openafs.org/dl/openafs/1.6.13/RELNOTES-1.6.13http://www.debian.org/security/2015/dsa-3320http://www.openafs.org/pages/security/OPENAFS-SA-2015-006.txthttps://lists.openafs.org/pipermail/openafs-announce/2015/000486.htmlhttps://www.openafs.org/dl/openafs/1.6.13/RELNOTES-1.6.13
2015-09-02
Published