VDB
CVE-2007-6599
CVE-2007-6599
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAllCallBacks RPC to perform linked-list operations without the host_glock lock.
EPSS 1.51% · 81.6th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
1.51%
81.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| debian | debian_linux | 3.1, 4.0 |
| openafs | openafs | 1.3.50, 1.5.0 |
Timeline
- Jan 4, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 1, 2022 CVE Updated
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 27132 vdb
- SUSE-SR:2008:002 vendor-advisory
- [OpenAFS-announce] 20071220 OpenAFS Security Advisory 2007-003: denial of service in OpenAFS fileserver mailing-list
- 28401 third-party-advisory
- 28327 third-party-advisory
- http://www.openafs.org/security/OPENAFS-SA-2007-003.txt url
- GLSA-200801-04 vendor-advisory
- 28433 third-party-advisory
- DSA-1458 vendor-advisory
- MDVSA-2008:207 vendor-advisory
- ADV-2008-0046 vdb
- 28636 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-6599 advisory