Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10914

Опубликовано: 04 сент. 2018
Источник: redhat
CVSS3: 5.5

Описание

It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.

Отчет

This issue did not affect Red Hat Enterprise Linux 6 and 7 as the flaw is present in glusterfs-server, which is not shipped there. This flaw affects glusterfs versions included in Red Hat Virtualization 4 Hypervisor. However, in recommended configurations, the vulnerability is only exposed to hypervisor administrators and can not be exploited from virtual machines or other hosts on the network.

Меры по смягчению последствий

SELinux mitigates this issue on Red Hat Gluster Storage 3. SELinux should be in enforcing mode only as permissive mode does not block attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6glusterfsNot affected
Red Hat Enterprise Linux 7glusterfsNot affected
Red Hat Enterprise Linux 8glusterfsNot affected
Native Client for RHEL 6 for Red Hat StorageglusterfsFixedRHSA-2018:260804.09.2018
Native Client for RHEL 7 for Red Hat StorageglusterfsFixedRHSA-2018:260704.09.2018
Red Hat Gluster Storage 3.4 for RHEL 6glusterfsFixedRHSA-2018:260804.09.2018
Red Hat Gluster Storage 3.4 for RHEL 6redhat-release-serverFixedRHSA-2018:260804.09.2018
Red Hat Gluster Storage 3.4 for RHEL 6redhat-storage-serverFixedRHSA-2018:260804.09.2018
Red Hat Gluster Storage 3.4 for RHEL 7glusterfsFixedRHSA-2018:260704.09.2018
Red Hat Gluster Storage 3.4 for RHEL 7redhat-release-serverFixedRHSA-2018:260704.09.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1607617glusterfs: remote denial of service of gluster volumes via posix_get_file_contents function in posix-helpers.c

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.

CVSS3: 6.5
nvd
больше 7 лет назад

It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.

CVSS3: 6.5
debian
больше 7 лет назад

It was found that an attacker could issue a xattr request via glusterf ...

CVSS3: 6.5
github
почти 4 года назад

It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.

suse-cvrf
около 6 лет назад

Security update for glusterfs

5.5 Medium

CVSS3