{"id":"MGASA-2016-0121","summary":"Updated openafs packages fix security vulnerability","details":"In OpenAFS before 1.6.17, users from foreign Kerberos realms can create\ngroups as if they were administrators (CVE-2016-2860).\n\nIn OpenAFS before 1.6.17, information leakage over the network due to\nuninitialized memory (CVE-2016-4536).\n","modified":"2026-04-16T06:23:48.832263563Z","published":"2016-03-25T06:38:37Z","upstream":["CVE-2016-2860","CVE-2016-4536"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0121.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=18034"},{"type":"WEB","url":"http://www.openafs.org/pages/security/OPENAFS-SA-2016-001.txt"},{"type":"WEB","url":"http://www.openafs.org/pages/security/OPENAFS-SA-2016-002.txt"},{"type":"WEB","url":"http://dl.openafs.org/dl/1.6.16/RELNOTES-1.6.16"},{"type":"WEB","url":"http://dl.openafs.org/dl/1.6.16/RELNOTES-1.6.17"},{"type":"WEB","url":"https://lists.openafs.org/pipermail/openafs-announce/2015/000495.html"},{"type":"WEB","url":"https://lists.openafs.org/pipermail/openafs-announce/2016/000496.html"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2016/05/05/23"}],"affected":[{"package":{"name":"openafs","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/openafs?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.17-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0121.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}