CVE-2018-10907Stack-based Buffer Overflow in Glusterfs

Severity
8.8HIGHNVD
EPSS
2.1%
top 16.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 4
Latest updateMay 13

Description

It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

NVDgluster/glusterfs3.12.03.12.14+1
Debiangluster/glusterfs< 4.1.4-1+3
CVEListV5red_hat/glusterfsn/a
NVDopensuse/leap15.1

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-h429-wm24-5m9h: It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc2022-05-13
OSV
CVE-2018-10907: It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc2018-09-04
CVEList
CVE-2018-10907: It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc2018-09-04

📋Vendor Advisories

3
Ubuntu
GlusterFS vulnerabilities2021-03-15
Red Hat
glusterfs: Stack-based buffer overflow in server-rpc-fops.c allows remote attackers to execute arbitrary code2018-09-04
Debian
CVE-2018-10907: glusterfs - It was found that glusterfs server is vulnerable to multiple stack based buffer ...2018

💬Community

4
Bugzilla
CVE-2018-10907 glusterfs: Stack-based buffer overflow in server-rpc-fops.c allows remote attackers to execute arbitrary code2018-09-05
Bugzilla
CVE-2018-10907 glusterfs: Stack-based buffer overflow in server-rpc-fops.c allows remote attackers to execute arbitrary code2018-09-04
Bugzilla
CVE-2018-10907 glusterfs: Stack-based buffer overflow in server-rpc-fops.c allows remote attackers to execute arbitrary code [fedora-all]2018-09-04
Bugzilla
CVE-2018-10907 glusterfs: Stack-based buffer overflow in server-rpc-fops.c allows remote attackers to execute arbitrary code2018-07-17
CVE-2018-10907 — Stack-based Buffer Overflow | cvebase