Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial of service (crash) via a crafted statsVersion argument.
http://www.openafs.org/frameset/dl/openafs/1.6.7/ChangeLog
http://www.debian.org/security/2014/dsa-2899
http://secunia.com/advisories/57832