cbcvebase.
CVE-2018-10911
published 2018-09-04

CVE-2018-10911: A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianglusterfs< glusterfs 4.1.4-1 (bookworm)glusterfs 4.1.4-1 (bookworm)
glusterglusterfs>= 0 < 4.1.4-14.1.4-1
glusterglusterfs>= 0 < 4.1.4-14.1.4-1
glusterglusterfs>= 0 < 4.1.4-14.1.4-1
glusterglusterfs>= 0 < 4.1.4-14.1.4-1
glusterglusterfs>= 0 < 3.4.2-1ubuntu1+esm13.4.2-1ubuntu1+esm1
glusterglusterfs>= 0 < 3.7.6-1ubuntu1+esm13.7.6-1ubuntu1+esm1
glusterglusterfs>= 0 < 3.13.2-1ubuntu1+esm13.13.2-1ubuntu1+esm1
glusterglusterfs>= 3.12.0 < 3.12.143.12.14
glusterglusterfs>= 4.1.0 < 4.1.84.1.8
opensuseleap
red_hatglusterfs
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
redhatvirtualization_host

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH