{"id":"MGASA-2017-0037","summary":"Updated openafs packages fix security vulnerability","details":"Due to incomplete initialization or clearing of reused memory, OpenAFS\ndirectory objects are likely to contain \"dead\" directory entry\ninformation. This extraneous information is not active - that is, it is\nlogically invisible to the fileserver and client. However, the leaked\ninformation is physically visible on the fileserver vice partition, on\nthe wire in FetchData replies and other RPCs, and on the client cache\npartition. This constitutes a leak of directory information\n(CVE-2016-9772).\n\nThe openafs package has been updated to version 1.6.20, to fix this\nissue and other bugs.\n","modified":"2026-04-16T06:24:22.690882818Z","published":"2017-02-02T19:17:14Z","upstream":["CVE-2016-9772"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2017-0037.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=19879"},{"type":"WEB","url":"https://www.openafs.org/pages/security/OPENAFS-SA-2016-003.txt"},{"type":"WEB","url":"http://openafs.org/dl/openafs/1.6.18.1/RELNOTES-1.6.18.1"},{"type":"WEB","url":"http://openafs.org/dl/openafs/1.6.18.2/RELNOTES-1.6.18.2"},{"type":"WEB","url":"http://openafs.org/dl/openafs/1.6.18.3/RELNOTES-1.6.18.3"},{"type":"WEB","url":"https://dl.openafs.org/dl/1.6.19/RELNOTES-1.6.19"},{"type":"WEB","url":"https://dl.openafs.org/dl/1.6.20/RELNOTES-1.6.20"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2016/12/02/9"}],"affected":[{"package":{"name":"openafs","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/openafs?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.20-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0037.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}