Cryptographic issues in OpenAFS and Debian Linux - CVE-2013-4135
Published: November 5, 2013 / Updated: August 10, 2020
Debian
OpenAFS
Debian Linux
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrity protection and sends data in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.