CVE-2014-4044 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-4044): OpenAFS 1.6.8 does not properly clear the fields in the host structure, which allows remote attackers to cause a denial of service (uninitialized memory access and crash) via unspecified vectors related to TMAY requests.
Upstream patch: http://openafs.org/pages/security/openafs-sa-2013-004.patch We currently don't have a 1.6.8 in the tree, but when I get some time, I'll see if I can test it for patch-application and compilation.
Fixed version 1.6.11 is in tree. Old unstable versions are removed.
Arch teams, please stabilize =net-fs/openafs-1.6.11.
amd64 stable
x86 stable
sparc stable. Maintainer(s), please cleanup. Security, please vote.
All vulnerable versions are removed from tree.
Arches and Maintainer(s), Thank you for your work. GLSA Vote: No
GLSA Vote: No