CVE-2014-3619
published 2015-03-27CVE-2014-3619: The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.72%
84.4th percentile
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glusterfs | < glusterfs 3.5.2-2 (bookworm) | glusterfs 3.5.2-2 (bookworm) |
| gluster | glusterfs | — | — |
| gluster | glusterfs | >= 0 < 3.5.2-2 | 3.5.2-2 |
| gluster | glusterfs | >= 0 < 3.5.2-2 | 3.5.2-2 |
| gluster | glusterfs | >= 0 < 3.5.2-2 | 3.5.2-2 |
| gluster | glusterfs | >= 0 < 3.5.2-2 | 3.5.2-2 |
| gluster | glusterfs | >= 0 < 3.4.2-1ubuntu1+esm1 | 3.4.2-1ubuntu1+esm1 |
| gluster | glusterfs | >= 0 < 3.7.6-1ubuntu1+esm1 | 3.7.6-1ubuntu1+esm1 |
| gluster | glusterfs | >= 0 < 3.13.2-1ubuntu1+esm1 | 3.13.2-1ubuntu1+esm1 |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7hxx-57vq-gp63: The __socket_proto_state_machine function in GlusterFS 3
ghsa_unreviewed·2022-05-14
CVE-2014-3619 [MEDIUM] GHSA-7hxx-57vq-gp63: The __socket_proto_state_machine function in GlusterFS 3
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
OSV
glusterfs vulnerabilities
osv·2021-03-15·CVSS 5.0
CVE-2014-3619 [MEDIUM] glusterfs vulnerabilities
glusterfs vulnerabilities
It was discovered that GlusterFS incorrectly handled network requests. An
attacker could possibly use this issue to cause a denial of service. This issue
only affected Ubuntu 14.04 ESM. (CVE-2014-3619)
It was discovered that GlusterFS incorrectly handled user permissions. An
authenticated attacker could possibly use this to add himself to a trusted
storage pool and perform privileged operations on volumes. This issue only
affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-10841)
It was discovered that GlusterFS incorrectly handled mounting gluster
volumes. An attacker could possibly use this issue to also mount shared
gluster volumes and escalate privileges through malicious cronjobs. This
issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2
OSV
CVE-2014-3619: The __socket_proto_state_machine function in GlusterFS 3
osv·2015-03-27·CVSS 5.0
CVE-2014-3619 [MEDIUM] CVE-2014-3619: The __socket_proto_state_machine function in GlusterFS 3
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
Ubuntu
GlusterFS vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 5.0
CVE-2018-10929 [MEDIUM] GlusterFS vulnerabilities
Title: GlusterFS vulnerabilities
Summary: Several security issues were fixed in GlusterFS.
It was discovered that GlusterFS incorrectly handled network requests. An
attacker could possibly use this issue to cause a denial of service. This issue
only affected Ubuntu 14.04 ESM. (CVE-2014-3619)
It was discovered that GlusterFS incorrectly handled user permissions. An
authenticated attacker could possibly use this to add himself to a trusted
storage pool and perform privileged operations on volumes. This issue only
affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-10841)
It was discovered that GlusterFS incorrectly handled mounting gluster
volumes. An attacker could possibly use this issue to also mount shared
gluster volumes and escalate privileges through malicious cronjobs. This
Red Hat
glusterfs: fragment header infinite loop DoS
vendor_redhat·2014-09-12·CVSS 5.0
CVE-2014-3619 [MEDIUM] CWE-835 glusterfs: fragment header infinite loop DoS
glusterfs: fragment header infinite loop DoS
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
A denial of service flaw was found in the way the __socket_proto_state_machine() function of glusterfs processed certain fragment headers. A remote attacker could send a specially crafted fragment header that, when processed, would cause the glusterfs process to enter an infinite loop.
Statement: Red Hat Storage 2.1 receives only qualified Important and Critical impact security fixes. This issue has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Support Matrix:
https://acce
Debian
CVE-2014-3619: glusterfs - The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attacke...
vendor_debian·2014·CVSS 5.0
CVE-2014-3619 [MEDIUM] CVE-2014-3619: glusterfs - The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attacke...
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
Scope: local
bookworm: resolved (fixed in 3.5.2-2)
bullseye: resolved (fixed in 3.5.2-2)
forky: resolved (fixed in 3.5.2-2)
sid: resolved (fixed in 3.5.2-2)
trixie: resolved (fixed in 3.5.2-2)
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0145.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00031.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00056.htmlhttp://review.gluster.org/#/c/8662/4http://www.mandriva.com/security/advisories?name=MDVSA-2015:211https://bugzilla.redhat.com/show_bug.cgi?id=1138145http://advisories.mageia.org/MGASA-2015-0145.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00031.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00056.htmlhttp://review.gluster.org/#/c/8662/4http://www.mandriva.com/security/advisories?name=MDVSA-2015:211https://bugzilla.redhat.com/show_bug.cgi?id=1138145
2015-03-27
Published