A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing the user to create a PAG using an existing id number, effectively joining the PAG and letting the user steal the credentials in that PAG.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "libafsauthent2t64" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "libafsauthent2t64-dbgsym" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "libafsrpc2t64" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "libafsrpc2t64-dbgsym" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "libkopenafs2t64" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "libkopenafs2t64-dbgsym" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "libopenafs-dev" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "libopenafs-dev-dbgsym" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "openafs-client" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "openafs-client-dbgsym" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "openafs-dbserver" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "openafs-dbserver-dbgsym" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "openafs-doc" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "openafs-fileserver" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "openafs-fileserver-dbgsym" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "openafs-fuse" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "openafs-fuse-dbgsym" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "openafs-krb5" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "openafs-krb5-dbgsym" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "openafs-modules-dkms" }, { "binary_version": "1.8.13.2-1ubuntu1", "binary_name": "openafs-modules-source" } ] }