[SECURITY] [DLA 4168-1] openafs security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4168-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Thorsten Alteholz
May 17, 2025 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : openafs
Version : 1.8.6-5+deb11u1
CVE ID : CVE-2024-10394 CVE-2024-10396 CVE-2024-10397
Debian Bug :
Several vulnerabilities were discovered in OpenAFS, an implementation of
the AFS distributed filesystem, which may result in theft of credentials
in Unix client PAGs (CVE-2024-10394), fileserver crashes and information
leak on StoreACL/FetchACL (CVE-2024-10396) or buffer overflows in XDR
responses resulting in denial of service and potentially code execution
(CVE-2024-10397).
For Debian 11 bullseye, these problems have been fixed in version
1.8.6-5+deb11u1.
We recommend that you upgrade your openafs packages.
For the detailed security status of openafs please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/openafs
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmgoug1fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEc+CQ//T9eFLJXlZXrEJCEXxgfORNJfoZ1Mxvgn/jnZU5VRlUSysFYh5RL3cTiB
ySL0Ydpsj76q0XnxTossAb1py7vpdNCai04IVmpl7+xNfqrP4wej/YG8sYUybS8g
s2Pcm7AbRqajwQsB/BRmy/b74XLzIrSmFQTSIvGOH/34FsaeYc+VOvdBEXtzxppv
Sh7NfFCDo4Hn90JTZTwwringjKTboutGHrDK10EsXcP/0i+HB8cMZY/47kDaviag
9fD/L6XBIHcgFJH83qfmgMrsU0j+GztPxcG6OYCDduwKhFFFN6uOuBLftVsaiPNf
pV6LguH86i2OeKXJU1hLfh53c8/PCyEVUAzHmM2j089uYTwCzBl8I5A1W2vJtIR1
vXI+i/h2Sfn1qZDvTKCS7Huayzeglzs/5wNJAT2ZC07O+C3j1yrIUJ5LyneV1A+U
Cqnd7lLrQL0bcuwXpPTacMAs8REencDu/CmjtUOTQ00TA7UWNa8QSqEZZqhe1k8u
V5aDPuGdhszzxQAr9EKnDGngSfV7itEkAz5B9h5Wo/BoNAw1UN/PRdwVLQU3oosj
D1CcJthPGh6P2pXVKHu6M6012NuP2akplMPubsX+P/A+VQfT1Ky/DWGj5zTZUXT5
3bbnwIaDJPpdCl6r+qo4vns/MI/giNbtA4tVFP497LtXPHbaLac=
=YPYo
-----END PGP SIGNATURE-----
Reply to: