Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-14660

Опубликовано: 01 нояб. 2018
Источник: debian
EPSS Низкий

Описание

A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glusterfsfixed5.1-1package
glusterfsnot-affectedjessiepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2018/10/31/5

  • https://bugzilla.redhat.com/show_bug.cgi?id=1635926

  • https://review.gluster.org/#/c/glusterfs/+/21531/

  • http://git.gluster.org/cgit/glusterfs.git/commit/?id=c2c70552188ee1b15bb748b4f2272062505c7696

EPSS

Процентиль: 81%
0.01601
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node.

CVSS3: 6.5
redhat
больше 7 лет назад

A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node.

CVSS3: 6.5
nvd
больше 7 лет назад

A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node.

CVSS3: 6.5
github
больше 3 лет назад

A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость файловой системы GlusterFS, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 81%
0.01601
Низкий