OpenAFS: Denial of service A Denial of Service vulnerability has been discovered in OpenAFS. openafs 2008-01-09 2008-01-09 203573 remote 1.4.6 1.4.6

OpenAFS is a distributed network filesystem.

Russ Allbery, Jeffrey Altman, Dan Hyde and Thomas Mueller discovered a race condition due to an improper handling of the clients callbacks lists.

A remote attacker could construct cases which trigger the race condition, resulting in a server crash.

There is no known workaround at this time.

All OpenAFS users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-fs/openafs-1.4.6"
CVE-2007-6599 rbu p-y p-y