CVE-2016-9772

NameCVE-2016-9772
DescriptionOpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2) fileserver vice partition, or (3) certain RPC responses.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-733-1
Debian Bugs846922

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openafs (PTS)jessie, jessie (lts)1.6.9-2+deb8u9fixed
stretch (security), stretch (lts), stretch1.6.20-2+deb9u2fixed
buster1.8.2-1+deb10u1fixed
bullseye1.8.6-5fixed
bookworm1.8.9-1fixed
sid1.8.12.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openafssourcewheezy1.6.1-3+deb7u7DLA-733-1
openafssourcejessie1.6.9-2+deb8u6
openafssource(unstable)1.6.20-1846922

Notes

https://www.openafs.org/pages/security/OPENAFS-SA-2016-003.txt
Upstream patch: https://www.openafs.org/pages/security/openafs-sa-2016-003-master.patch (master)
Upstream patch: https://www.openafs.org/pages/security/openafs-sa-2016-003.patch
https://www.openwall.com/lists/oss-security/2016/12/01/12

Search for package or bug name: Reporting problems