Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10924

Опубликовано: 04 сент. 2018
Источник: debian
EPSS Низкий

Описание

It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glusterfsfixed4.0.1-1package
glusterfsnot-affectedstretchpackage
glusterfsnot-affectedjessiepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1611785

  • Introduced by: http://git.gluster.org/cgit/glusterfs.git/commit/?id=51dfc9c789b8405f595a337eade938aedcb449c4

  • https://review.gluster.org/20723

EPSS

Процентиль: 78%
0.01881
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 8 лет назад

It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.

CVSS3: 5.3
redhat
почти 8 лет назад

It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.

CVSS3: 5.3
nvd
почти 8 лет назад

It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.

CVSS3: 6.5
github
больше 4 лет назад

It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.

suse-cvrf
больше 6 лет назад

Security update for glusterfs

EPSS

Процентиль: 78%
0.01881
Низкий