CVE-2013-1794

medium
Published 2013-03-14 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
6.5

Description

Buffer overflow in certain client utilities in OpenAFS before 1.6.2 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long fileserver ACL entry.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.6.1-3
debian debianbullseyefixed1.6.1-3
debian debiansidfixed1.6.1-3
debian debiantrixiefixed1.6.1-3

Application impact

VendorProductVersionsFixed
openafsopenafs{"endIncluding":"1.6.1"}
openafsopenafs1.5.10
openafsopenafs1.5.11
openafsopenafs1.5.12
openafsopenafs1.5.13
openafsopenafs1.5.14
openafsopenafs1.5.15
openafsopenafs1.5.16
openafsopenafs1.5.17
openafsopenafs1.5.18
openafsopenafs1.5.19
openafsopenafs1.5.20
openafsopenafs1.5.21
openafsopenafs1.5.22
openafsopenafs1.5.23
openafsopenafs1.5.24
openafsopenafs1.5.25
openafsopenafs1.5.26
openafsopenafs1.5.27
openafsopenafs1.5.28
openafsopenafs1.5.29
openafsopenafs1.5.30
openafsopenafs1.5.31
openafsopenafs1.5.32
openafsopenafs1.5.33
openafsopenafs1.5.34
openafsopenafs1.5.35
openafsopenafs1.5.36
openafsopenafs1.5.37
openafsopenafs1.5.38
openafsopenafs1.5.39
openafsopenafs1.5.50
openafsopenafs1.5.51
openafsopenafs1.5.52
openafsopenafs1.5.53
openafsopenafs1.5.54
openafsopenafs1.5.55
openafsopenafs1.5.56
openafsopenafs1.5.57
openafsopenafs1.5.58
openafsopenafs1.5.59
openafsopenafs1.5.60
openafsopenafs1.5.61
openafsopenafs1.5.62
openafsopenafs1.5.63
openafsopenafs1.5.64
openafsopenafs1.5.65
openafsopenafs1.5.66
openafsopenafs1.5.67
openafsopenafs1.5.68
openafsopenafs1.5.69
openafsopenafs1.5.70
openafsopenafs1.5.71
openafsopenafs1.5.72
openafsopenafs1.5.73
openafsopenafs1.5.74
openafsopenafs1.5.75
openafsopenafs1.5.76
openafsopenafs1.5.77
openafsopenafs1.5.78
openafsopenafs1.6.0

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.