CVE-2019-18601
published 2019-10-29CVE-2019-18601: OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series of…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.40%
69.3th percentile
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to crash a database server within the SVOTE_Debug RPC handler.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openafs | < openafs 1.8.5-1 (bookworm) | openafs 1.8.5-1 (bookworm) |
| openafs | openafs | < 1.6.24 | 1.6.24 |
| openafs | openafs | >= 0 < 1.8.5-1 | 1.8.5-1 |
| openafs | openafs | >= 0 < 1.8.5-1 | 1.8.5-1 |
| openafs | openafs | >= 0 < 1.8.5-1 | 1.8.5-1 |
| openafs | openafs | >= 1.8.0 < 1.8.5 | 1.8.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m28x-w8m6-pc3f: OpenAFS before 1
ghsa_unreviewed·2022-05-24
CVE-2019-18601 [HIGH] CWE-502 GHSA-m28x-w8m6-pc3f: OpenAFS before 1
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to crash a database server within the SVOTE_Debug RPC handler.
OSV
CVE-2019-18601: OpenAFS before 1
osv·2019-10-29·CVSS 7.5
CVE-2019-18601 [HIGH] CVE-2019-18601: OpenAFS before 1
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to crash a database server within the SVOTE_Debug RPC handler.
Debian
CVE-2019-18601: openafs - OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from ...
vendor_debian·2019·CVSS 7.5
CVE-2019-18601 [HIGH] CVE-2019-18601: openafs - OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from ...
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to crash a database server within the SVOTE_Debug RPC handler.
Scope: local
bookworm: resolved (fixed in 1.8.5-1)
bullseye: resolved (fixed in 1.8.5-1)
sid: resolved (fixed in 1.8.5-1)
trixie: resolved (fixed in 1.8.5-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-10-29
Published