Debian Security Advisory DSA 1458-1 (openafs)

Summary
The remote host is missing an update to openafs announced via advisory DSA 1458-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201458-1
Insight
A race condition in the OpenAFS fileserver allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAllCallBacks RPC to perform linked-list operations without the host_glock lock. For the stable distribution (etch), this problem has been fixed in version 1.4.2-6etch1 For the old stable distribution (sarge), this problem has been fixed in version 1.3.81-3sarge3 We recommend that you upgrade your openafs packages.