Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10924

Опубликовано: 04 сент. 2018
Источник: debian
EPSS Низкий

Описание

It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glusterfsfixed4.0.1-1package
glusterfsnot-affectedstretchpackage
glusterfsnot-affectedjessiepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1611785

  • Introduced by: http://git.gluster.org/cgit/glusterfs.git/commit/?id=51dfc9c789b8405f595a337eade938aedcb449c4

  • https://review.gluster.org/20723

EPSS

Процентиль: 72%
0.00728
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.

CVSS3: 5.3
redhat
больше 7 лет назад

It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.

CVSS3: 5.3
nvd
больше 7 лет назад

It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.

CVSS3: 6.5
github
больше 3 лет назад

It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.

suse-cvrf
около 6 лет назад

Security update for glusterfs

EPSS

Процентиль: 72%
0.00728
Низкий