Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h429-wm24-5m9h

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.

It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.

EPSS

Процентиль: 84%
0.02169
Низкий

8.8 High

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.

CVSS3: 8.8
redhat
больше 7 лет назад

It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.

CVSS3: 8.8
nvd
больше 7 лет назад

It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.

CVSS3: 8.8
debian
больше 7 лет назад

It was found that glusterfs server is vulnerable to multiple stack bas ...

suse-cvrf
около 6 лет назад

Security update for glusterfs

EPSS

Процентиль: 84%
0.02169
Низкий

8.8 High

CVSS3

Дефекты

CWE-121