Описание
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
A denial of service flaw was found in the way the __socket_proto_state_machine() function of glusterfs processed certain fragment headers. A remote attacker could send a specially crafted fragment header that, when processed, would cause the glusterfs process to enter an infinite loop.
Отчет
Red Hat Storage 2.1 receives only qualified Important and Critical impact security fixes. This issue has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Support Matrix: https://access.redhat.com/support/policy/updates/rhs
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | glusterfs | Affected | ||
| Red Hat Enterprise Linux 6 | glusterfs | Affected | ||
| Red Hat Enterprise Linux 7 | glusterfs | Affected | ||
| Native Client for RHEL 5 for Red Hat Storage | glusterfs | Fixed | RHBA-2015:0038 | 15.01.2015 |
| Native Client for RHEL 6 for Red Hat Storage | glusterfs | Fixed | RHBA-2015:0038 | 15.01.2015 |
| Red Hat Common for RHEL 7 | glusterfs | Fixed | RHBA-2015:0040 | 15.01.2015 |
| Red Hat Storage 3 for RHEL 6 | glusterfs | Fixed | RHBA-2015:0038 | 15.01.2015 |
| Red Hat Storage 3 for RHEL 6 | gluster-nagios-addons | Fixed | RHBA-2015:0038 | 15.01.2015 |
| Red Hat Storage 3 for RHEL 6 | gluster-nagios-common | Fixed | RHBA-2015:0038 | 15.01.2015 |
| Red Hat Storage 3 for RHEL 6 | gstatus | Fixed | RHBA-2015:0038 | 15.01.2015 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS2
Связанные уязвимости
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
The __socket_proto_state_machine function in GlusterFS 3.5 allows remo ...
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
EPSS
5 Medium
CVSS2