
CVE-2015-3284 – Debian Security Advisory 3320-1
https://notcve.org/view.php?id=CVE-2015-3284
03 Aug 2015 — pioctls in OpenAFS 1.6.x before 1.6.13 allows local users to read kernel memory via crafted commands. Vulnerabilidad en pioctls en OpenAFS 1.6.x en versiones anteriores a 1.6.13, permite a usuarios locales leer la memoria del kernel a través de comandos manipulados. It was discovered that OpenAFS, the implementation of the distributed filesystem AFS, contained several flaws that could result in information leak, denial-of-service or kernel panic. • http://www.debian.org/security/2015/dsa-3320 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2015-3285 – Debian Security Advisory 3320-1
https://notcve.org/view.php?id=CVE-2015-3285
03 Aug 2015 — The pioctl for the OSD FS command in OpenAFS before 1.6.13 uses the wrong pointer when writing the results of the RPC, which allows local users to cause a denial of service (memory corruption and kernel panic) via a crafted OSD FS command. Vulnerabilidad en el pioctl para el comando OSD FS en OpenAFS en versiones anteriores a 1.6.13, usa el puntero incorrecto cuando escribe los resultados del RPC, lo que permite a usuarios locales causar una denegación de servicio (corrupción de memoria y kernel panic) a tr... • http://www.debian.org/security/2015/dsa-3320 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2014-4044
https://notcve.org/view.php?id=CVE-2014-4044
17 Jun 2014 — OpenAFS 1.6.8 does not properly clear the fields in the host structure, which allows remote attackers to cause a denial of service (uninitialized memory access and crash) via unspecified vectors related to TMAY requests. OpenAFS versión 1.6.8, no limpia apropiadamente los campos en la estructura del host, lo que permite a los atacantes remotos causar una denegación de servicio (acceso a la memoria no inicializada y bloqueo) por medio de vectores no especificados relacionados con peticiones TMAY. • http://gerrit.openafs.org/#change%2C11283 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-4134 – Mandriva Linux Security Advisory 2014-244
https://notcve.org/view.php?id=CVE-2013-4134
29 Jul 2013 — OpenAFS before 1.4.15, 1.6.x before 1.6.5, and 1.7.x before 1.7.26 uses weak encryption (DES) for Kerberos keys, which makes it easier for remote attackers to obtain the service key. OpenAFS anterior a 1.4.15, 1.6.x anterior a 1.6.5 y 1.7.x anterior a 1.7.26 utiliza cifrado débil (DES) para las claves de Kerberos, lo que hace que sea más fácil para los atacantes remotos para obtener la clave de servicio. Buffer overflow in certain client utilities in OpenAFS before 1.6.2 allows remote authenticated users to... • http://www.debian.org/security/2013/dsa-2729 • CWE-310: Cryptographic Issues •