>> OpenAFS "GiveUpAllCallBacks" Handler Denial of Service Vulnerability
Title : OpenAFS "GiveUpAllCallBacks" Handler Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-0046 CVE ID : CVE-2007-6599
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-01-07
Technical Description
A vulnerability has been identified in OpenAFS, which could be exploited by attackers to cause a denial of service. This issue is caused by a race condition within the "GiveUpAllCallBacks" RPC handler when simultaneously acquiring and giving back file callbacks, which could be exploited by attackers to crash a vulnerable server, creating a denial of service condition.