OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer.
| Software | From | Fixed in |
|---|---|---|
| openafs / openafs | 1.8.0 | 1.8.5 |
| openafs / openafs | - | 1.6.24 |
| debian / debian_linux | 8.0 | 8.0.x |