CVE-2013-4134: Debian Linux

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

OpenAFS before 1.4.15, 1.6.x before 1.6.5, and 1.7.x before 1.7.26 uses weak encryption (DES) for Kerberos keys, which makes it easier for remote attackers to obtain the service key.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Openafs Openafs: up to and including 1.4.14; version 1.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; …

Published 2013-11-05. Last modified 2026-06-16.