Unrated severityNVD Advisory· Published Apr 14, 2014· Updated May 6, 2026
CVE-2014-0159
CVE-2014-0159
Description
Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial of service (crash) via a crafted statsVersion argument.
Affected products
19cpe:2.3:a:openafs:openafs:1.4.10:*:*:*:*:*:*:*+ 17 more
- cpe:2.3:a:openafs:openafs:1.4.10:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.4.11:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.4.12:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.4.14:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.4.14.1:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.4.15:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.4.8:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.4.9:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.6.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.6.4:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.6.5:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.6.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.6.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:openafs:openafs:1.6.6:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- openafs.org/pages/security/OPENAFS-SA-2014-001.txtnvdVendor Advisory
- secunia.com/advisories/57779nvdPermissions RequiredThird Party Advisory
- secunia.com/advisories/57832nvdPermissions RequiredThird Party Advisory
- www.debian.org/security/2014/dsa-2899nvdThird Party Advisory
- www.mandriva.com/security/advisoriesnvdBroken Link
- www.openafs.org/frameset/dl/openafs/1.6.7/ChangeLognvdIssue TrackingRelease Notes
News mentions
0No linked articles in our index yet.