Search CVE reports
11 – 20 of 29 results
CVE-2018-10929
Medium prioritySome fixes available 3 of 4
A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files and execute arbitrary code on glusterfs server nodes.
1 affected packages
glusterfs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
glusterfs | — | Not affected | Not affected | Fixed | Fixed |
CVE-2018-10928
Medium prioritySome fixes available 3 of 4
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary...
1 affected packages
glusterfs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
glusterfs | — | Not affected | Not affected | Fixed | Fixed |
CVE-2018-10927
Medium prioritySome fixes available 3 of 4
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process.
1 affected packages
glusterfs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
glusterfs | — | Not affected | Not affected | Fixed | Fixed |
CVE-2018-10926
Medium prioritySome fixes available 3 of 4
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a glusterfs...
1 affected packages
glusterfs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
glusterfs | — | Not affected | Not affected | Fixed | Fixed |
CVE-2018-10924
Medium priorityIt was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.
1 affected packages
glusterfs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
glusterfs | — | Not affected | Not affected | Fixed | Not affected |
CVE-2018-10923
Medium prioritySome fixes available 3 of 4
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any...
1 affected packages
glusterfs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
glusterfs | — | Not affected | Not affected | Fixed | Fixed |
CVE-2018-10914
Medium prioritySome fixes available 3 of 4
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash...
1 affected packages
glusterfs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
glusterfs | — | Not affected | Not affected | Fixed | Fixed |
CVE-2018-10913
Medium prioritySome fixes available 3 of 4
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.
1 affected packages
glusterfs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
glusterfs | — | Not affected | Not affected | Fixed | Fixed |
CVE-2018-10911
Medium prioritySome fixes available 3 of 4
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
1 affected packages
glusterfs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
glusterfs | — | Not affected | Not affected | Fixed | Fixed |
CVE-2018-10907
Medium prioritySome fixes available 3 of 4
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by...
1 affected packages
glusterfs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
glusterfs | — | Not affected | Not affected | Fixed | Fixed |