CVE-2009-1250
Last modified
CVE-2009-1250 is a vulnerability of currently unknown severity. The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.. EPSS estimates a 3.98% chance of exploitation in the next 30 days.
Description
The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ibm | Afs | <= 3.6 | Patch18 |
| Ibm | Afs | 3.6 | — |
| Openafs | Openafs | 1.0 | — |
| Openafs | Openafs | 1.0.1 | — |
| Openafs | Openafs | 1.0.2 | — |
| Openafs | Openafs | 1.0.3 | — |
| Openafs | Openafs | 1.0.4 | — |
| Openafs | Openafs | 1.0.4a | — |
| Openafs | Openafs | 1.1 | — |
| Openafs | Openafs | 1.1.0 | — |
| Openafs | Openafs | 1.1.1 | — |
| Openafs | Openafs | 1.1.1a | — |
| Openafs | Openafs | 1.2 | — |
| Openafs | Openafs | 1.2.1 | — |
| Openafs | Openafs | 1.2.2 | — |
| Openafs | Openafs | 1.2.2a | — |
| Openafs | Openafs | 1.2.2b | — |
| Openafs | Openafs | 1.2.3 | — |
| Openafs | Openafs | 1.2.4 | — |
| Openafs | Openafs | 1.2.5 | — |
| Openafs | Openafs | 1.2.6 | — |
| Openafs | Openafs | 1.2.7 | — |
| Openafs | Openafs | 1.2.8 | — |
| Openafs | Openafs | 1.2.9 | — |
| Openafs | Openafs | 1.2.10 | — |
| Openafs | Openafs | 1.2.11 | — |
| Openafs | Openafs | 1.2.13 | — |
| Openafs | Openafs | 1.3 | — |
| Openafs | Openafs | 1.3.1 | — |
| Openafs | Openafs | 1.3.2 | — |
| Openafs | Openafs | 1.3.5 | — |
| Openafs | Openafs | 1.3.70 | — |
| Openafs | Openafs | 1.3.74 | — |
| Openafs | Openafs | 1.3.77 | — |
| Openafs | Openafs | 1.3.81 | — |
| Openafs | Openafs | 1.4 | — |
| Openafs | Openafs | 1.4.0 | — |
| Openafs | Openafs | 1.4.3 | — |
| Openafs | Openafs | 1.4.4 | — |
| Openafs | Openafs | 1.4.5 | — |
| Openafs | Openafs | 1.4.6 | — |
| Openafs | Openafs | 1.4.7 | — |
| Openafs | Openafs | 1.4.7_pre1 | — |
| Openafs | Openafs | 1.4.7_pre2 | — |
| Openafs | Openafs | 1.4.7_pre3 | — |
| Openafs | Openafs | 1.4.7_pre4 | — |
| Openafs | Openafs | 1.4.7_pre5 | — |
| Openafs | Openafs | 1.4.8 | — |
| Openafs | Openafs | 1.4.8_pre1 | — |
| Openafs | Openafs | 1.4.8_pre2 | — |
Showing 50 of 73 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-1250?
How severe is CVE-2009-1250?
How do I fix CVE-2009-1250?
Are you affected by CVE-2009-1250?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
