cbcvebase.
CVE-2018-14653
published 2018-10-31

CVE-2018-14653: The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_getspec_req' RPC message. A remote authenticated attacker could exploit this to cause a denial of service or other potential unspecified impact.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianglusterfs< glusterfs 5.1-1 (bookworm)glusterfs 5.1-1 (bookworm)
glusterglusterfs>= 0 < 5.1-15.1-1
glusterglusterfs>= 0 < 5.1-15.1-1
glusterglusterfs>= 0 < 5.1-15.1-1
glusterglusterfs>= 0 < 5.1-15.1-1
glusterglusterfs>= 0 < 3.4.2-1ubuntu1+esm13.4.2-1ubuntu1+esm1
glusterglusterfs>= 0 < 3.7.6-1ubuntu1+esm13.7.6-1ubuntu1+esm1
glusterglusterfs>= 0 < 3.13.2-1ubuntu1+esm13.13.2-1ubuntu1+esm1
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_virtualization
redhatgluster_storage3.0.0 – 3.1.2
redhatgluster_storage4.1.0 – 4.1.4
the_gluster_projectglusterfs

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH