Search CVE reports


Toggle filters

11 – 20 of 29 results


CVE-2018-10929

Medium priority

Some fixes available 3 of 4

A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files and execute arbitrary code on glusterfs server nodes.

1 affected package

glusterfs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
glusterfs Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-10928

Medium priority

Some fixes available 3 of 4

A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary...

1 affected package

glusterfs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
glusterfs Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-10927

Medium priority

Some fixes available 3 of 4

A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process.

1 affected package

glusterfs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
glusterfs Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-10926

Medium priority

Some fixes available 3 of 4

A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a glusterfs...

1 affected package

glusterfs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
glusterfs Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-10924

Medium priority
Fixed

It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.

1 affected package

glusterfs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
glusterfs Not affected Not affected Fixed Not affected
Show less packages

CVE-2018-10923

Medium priority

Some fixes available 3 of 4

It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any...

1 affected package

glusterfs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
glusterfs Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-10914

Medium priority

Some fixes available 3 of 4

It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash...

1 affected package

glusterfs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
glusterfs Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-10913

Medium priority

Some fixes available 3 of 4

An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.

1 affected package

glusterfs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
glusterfs Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-10911

Medium priority

Some fixes available 3 of 4

A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.

1 affected package

glusterfs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
glusterfs Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-10907

Medium priority

Some fixes available 3 of 4

It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by...

1 affected package

glusterfs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
glusterfs Not affected Not affected Fixed Fixed
Show less packages