The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.
{ "binaries": [ { "binary_name": "libafsauthent1", "binary_version": "1.6.7-1ubuntu1.1" }, { "binary_name": "libafsrpc1", "binary_version": "1.6.7-1ubuntu1.1" }, { "binary_name": "libkopenafs1", "binary_version": "1.6.7-1ubuntu1.1" }, { "binary_name": "libopenafs-dev", "binary_version": "1.6.7-1ubuntu1.1" }, { "binary_name": "libpam-openafs-kaserver", "binary_version": "1.6.7-1ubuntu1.1" }, { "binary_name": "openafs-client", "binary_version": "1.6.7-1ubuntu1.1" }, { "binary_name": "openafs-dbserver", "binary_version": "1.6.7-1ubuntu1.1" }, { "binary_name": "openafs-fileserver", "binary_version": "1.6.7-1ubuntu1.1" }, { "binary_name": "openafs-fuse", "binary_version": "1.6.7-1ubuntu1.1" }, { "binary_name": "openafs-kpasswd", "binary_version": "1.6.7-1ubuntu1.1" }, { "binary_name": "openafs-krb5", "binary_version": "1.6.7-1ubuntu1.1" }, { "binary_name": "openafs-modules-dkms", "binary_version": "1.6.7-1ubuntu1.1" }, { "binary_name": "openafs-modules-source", "binary_version": "1.6.7-1ubuntu1.1" } ], "availability": "No subscription required" }