- -------------------------------------------------------------------------
Debian Security Advisory DSA-5842-1                   security@debian.org
https://www.debian.org/security/                     Salvatore Bonaccorso
January 11, 2025                      https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : openafs
CVE ID         : CVE-2024-10394 CVE-2024-10396 CVE-2024-10397
Debian Bug     : 1087406 1087407

Several vulnerabilities were discovered in OpenAFS, an implementation of
the AFS distributed filesystem, which may result in theft of credentials
in Unix client PAGs (CVE-2024-10394), fileserver crashes and information
leak on StoreACL/FetchACL (CVE-2024-10396) or buffer overflows in XDR
responses resulting in denial of service and potentially code execution
(CVE-2024-10397).

For the stable distribution (bookworm), these problems have been fixed
in version 1.8.9-1+deb12u1.

We recommend that you upgrade your openafs packages.

For the detailed security status of openafs please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/openafs

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Debian: DSA-5842-1: openafs Security Advisory Updates

January 11, 2025
Several vulnerabilities were discovered in OpenAFS, an implementation of the AFS distributed filesystem, which may result in theft of credentials in Unix client PAGs (CVE-2024-1039...

Summary

For the stable distribution (bookworm), these problems have been fixed
in version 1.8.9-1+deb12u1.

We recommend that you upgrade your openafs packages.

For the detailed security status of openafs please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/openafs

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
Package : openafs
CVE ID : CVE-2024-10394 CVE-2024-10396 CVE-2024-10397

Related News