Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-26253

Опубликовано: 21 фев. 2023
Источник: redhat
CVSS3: 7.5

Описание

In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.

A flaw was found in Gluster, where GlusterFS is vulnerable to a denial of service caused by a stack-based buffer over-read flaw in xlators/mount/fuse/src/fuse-bridge.c. A remote attacker can cause the application to crash by sending a specially-crafted request.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6glusterfsNot affected
Red Hat Enterprise Linux 7glusterfsNot affected
Red Hat Enterprise Linux 8glusterfsNot affected
Red Hat Enterprise Linux 9glusterfsNot affected
Red Hat Storage 3glusterfsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2173923glusterfs: stack-based buffer overflow in notify() in fuse-bridge.c

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.

CVSS3: 7.5
nvd
почти 3 года назад

In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.

CVSS3: 7.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.5
debian
почти 3 года назад

In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bri ...

CVSS3: 9.1
github
почти 3 года назад

In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.

7.5 High

CVSS3