Описание
A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service.
Отчет
To exploit this issue, an attacker needs a user to connect to a malicious AFP share (for example, by clicking a crafted afp:// link), limiting its exposure. Furthermore, the direct security impact of this flaw is a denial of service due to the heap-based buffer overflow. For these reasons, this vulnerability has been rated with a moderate severity.
Меры по смягчению последствий
To mitigate this vulnerability, do not connect to untrusted AFP servers.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | gvfs | Fix deferred | ||
| Red Hat Enterprise Linux 6 | gvfs | Out of support scope | ||
| Red Hat Enterprise Linux 7 | gvfs | Fix deferred | ||
| Red Hat Enterprise Linux 8 | gvfs | Fix deferred | ||
| Red Hat Enterprise Linux 9 | gvfs | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
(A flaw was found in the AFP backend in gvfs. When mounting a share, a ...)
A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service.
A flaw was found in the AFP backend in gvfs. When mounting a share, a ...
A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service.
EPSS
6.5 Medium
CVSS3