Debian Glusterfs vulnerabilities
27 known vulnerabilities affecting debian/glusterfs.
Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH14MEDIUM10LOW3
Vulnerabilities
Page 2 of 2
CVE-2018-14652P4MEDIUMCVSS 6.5fixed in glusterfs 5.0-1 (bookworm)2018
CVE-2018-14652 [MEDIUM] CVE-2018-14652: glusterfs - The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffe...
The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote authenticated attacker could exploit this on a mounted volume to cause a denial of service.
Scope: local
bookworm: resolved (fixed in 5.0-1)
bull
debian
CVE-2018-10924P4MEDIUMCVSS 5.3fixed in glusterfs 4.0.1-1 (bookworm)2018
CVE-2018-10924 [MEDIUM] CVE-2018-10924: glusterfs - It was discovered that fsync(2) system call in glusterfs client code leaks memor...
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.
Scope: local
bookworm: resolved (fixed in 4.0.1-1)
bullseye: resolved (fixed in 4.0.1-1)
forky: resolved (fixed in 4.0.1-1)
sid: resolve
debian
CVE-2018-10914P4MEDIUMCVSS 6.5fixed in glusterfs 4.1.4-1 (bookworm)2018
CVE-2018-10914 [MEDIUM] CVE-2018-10914: glusterfs - It was found that an attacker could issue a xattr request via glusterfs FUSE to ...
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.
Scope: local
bookworm: resolved (fixed in 4.1.4-1)
bullseye: resolved (fixed in 4.1.4-1)
forky:
debian
CVE-2014-3619P4MEDIUMCVSS 5.0fixed in glusterfs 3.5.2-2 (bookworm)2014
CVE-2014-3619 [MEDIUM] CVE-2014-3619: glusterfs - The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attacke...
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
Scope: local
bookworm: resolved (fixed in 3.5.2-2)
bullseye: resolved (fixed in 3.5.2-2)
forky: resolved (fixed in 3.5.2-2)
sid: resolved (fixed in 3.5.2-2)
trixie: resolved (fixed in 3.5.2-2)
debian
CVE-2012-4417P4LOWCVSS 3.6fixed in glusterfs 3.2.7-5 (bookworm)2012
CVE-2012-4417 [LOW] CVE-2012-4417: glusterfs - GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to ov...
GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Scope: local
bookworm: resolved (fixed in 3.2.7-5)
bullseye: resolved (fixed in 3.2.7-5)
forky: resolved (fixed in 3.2.7-5)
sid: resolved (fixed in 3.2.7-5)
trixie: resolved (fixed in 3.2.7-5)
debian
CVE-2012-5635P4LOWCVSS 3.6fixed in glusterfs 3.5.0-1 (bookworm)2012
CVE-2012-5635 [LOW] CVE-2012-5635: glusterfs - The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Cl...
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.
Scope: local
bookworm:
debian
CVE-2017-15096P4LOWCVSS 3.3fixed in glusterfs 3.12.2-2 (bookworm)2017
CVE-2017-15096 [LOW] CVE-2017-15096: glusterfs - A flaw was found in GlusterFS in versions prior to 3.10. A null pointer derefere...
A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
Scope: local
bookworm: resolved (fixed in 3.12.2-2)
bullseye: resolved (fixed in 3.12.2-2)
forky: resolved (fixed in 3.12.2-2)
sid: resolved (fixed in 3.12.2-2)
trixie: resolved (fixed i
debian
← Previous2 / 2