Security Advisory

CVE-2018-16949

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-09-12 01:00:00
Last updated 2024-08-05 10:39:58
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables were implemented as unbounded array types, limited only by the inherent 32-bit length field to 4 GB. An unauthenticated attacker could send, or claim to send, large input values and consume server resources waiting for those inputs, denying service to other valid connections.