cvelist/2016/4xxx/CVE-2016-4536.json

73 lines
2.2 KiB
JSON
Raw Normal View History

2017-10-16 12:31:07 -04:00
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2016-4536",
"STATE" : "PUBLIC"
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a",
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
},
"vendor_name" : "n/a"
}
]
}
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "The client in OpenAFS before 1.6.17 does not properly initialize the (1) AFSStoreStatus, (2) AFSStoreVolumeStatus, (3) VldbListByAttributes, and (4) ListAddrByAttributes structures, which might allow remote attackers to obtain sensitive memory information by leveraging access to RPC call traffic."
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "n/a"
}
]
}
]
},
"references" : {
"reference_data" : [
{
"name" : "[OpenAFS-announce] 20160316 OpenAFS security release 1.6.17 available",
"refsource" : "MLIST",
2017-10-16 12:31:07 -04:00
"url" : "https://lists.openafs.org/pipermail/openafs-announce/2016/000496.html"
},
{
"name" : "https://www.openafs.org/dl/openafs/1.6.17/RELNOTES-1.6.17",
"refsource" : "CONFIRM",
2017-10-16 12:31:07 -04:00
"url" : "https://www.openafs.org/dl/openafs/1.6.17/RELNOTES-1.6.17"
},
{
"name" : "https://www.openafs.org/pages/security/OPENAFS-SA-2016-002.txt",
"refsource" : "CONFIRM",
2017-10-16 12:31:07 -04:00
"url" : "https://www.openafs.org/pages/security/OPENAFS-SA-2016-002.txt"
}
]
}
}