Improper Initialization of Structures in OpenAFS Client Allows Information Disclosure

Improper Initialization of Structures in OpenAFS Client Allows Information Disclosure

CVE-2016-4536 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

The client in OpenAFS before 1.6.17 does not properly initialize the (1) AFSStoreStatus, (2) AFSStoreVolumeStatus, (3) VldbListByAttributes, and (4) ListAddrByAttributes structures, which might allow remote attackers to obtain sensitive memory information by leveraging access to RPC call traffic.

Learn more about our Web Application Penetration Testing UK.