CVE-2018-3619
published 2018-07-10CVE-2018-3619: Information disclosure vulnerability in storage media in systems with Intel Optane memory module with Whole Disk Encryption may allow an attacker to recover…
PriorityP417medium4.6CVSS 3.0
AVPACLPRNUINSUCHINAN
EPSS
0.22%
12.1th percentile
Information disclosure vulnerability in storage media in systems with Intel Optane memory module with Whole Disk Encryption may allow an attacker to recover data via physical access.
Affected
124 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gluster | glusterfs | >= 0 < 3.4.2-1ubuntu1+esm1 | 3.4.2-1ubuntu1+esm1 |
| gluster | glusterfs | >= 0 < 3.7.6-1ubuntu1+esm1 | 3.7.6-1ubuntu1+esm1 |
| gluster | glusterfs | >= 0 < 3.13.2-1ubuntu1+esm1 | 3.13.2-1ubuntu1+esm1 |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
CVSS provenance
nvdv3.04.6MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fgf9-xx3c-6m8g: Information disclosure vulnerability in storage media in systems with Intel Optane memory module with Whole Disk Encryption may allow an attacker to r
ghsa_unreviewed·2022-05-13
CVE-2018-3619 [MEDIUM] CWE-200 GHSA-fgf9-xx3c-6m8g: Information disclosure vulnerability in storage media in systems with Intel Optane memory module with Whole Disk Encryption may allow an attacker to r
Information disclosure vulnerability in storage media in systems with Intel Optane memory module with Whole Disk Encryption may allow an attacker to recover data via physical access.
OSV
glusterfs vulnerabilities
osv·2021-03-15·CVSS 5.0
CVE-2014-3619 glusterfs vulnerabilities
glusterfs vulnerabilities
It was discovered that GlusterFS incorrectly handled network requests. An
attacker could possibly use this issue to cause a denial of service. This issue
only affected Ubuntu 14.04 ESM. (CVE-2014-3619)
It was discovered that GlusterFS incorrectly handled user permissions. An
authenticated attacker could possibly use this to add himself to a trusted
storage pool and perform privileged operations on volumes. This issue only
affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-10841)
It was discovered that GlusterFS incorrectly handled mounting gluster
volumes. An attacker could possibly use this issue to also mount shared
gluster volumes and escalate privileges through malicious cronjobs. This
issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-07-10
Published