The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_getspec_req' RPC message. A remote authenticated attacker could exploit this to cause a denial of service or other potential unspecified impact.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade glusterfs-server | Aug 28, 2019 | Oct 31, 2018 |
| Debian | — | Upgrade glusterfs | Feb 19, 2019 | Oct 31, 2018 |
| Gentoo Linux | — | Upgrade sys-cluster/glusterfs. | Apr 3, 2019 | Oct 31, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade glusterfs-develUpgrade glusterfs-cliUpgrade glusterfs-libsUpgrade glusterfsUpgrade glusterfs-fuseUpgrade glusterfs-api-develUpgrade python2-glusterUpgrade glusterfs-apiUpgrade glusterfs-rdmaUpgrade glusterfs-client-xlatorsUpgrade glusterfs-extra-xlatorsUpgrade glusterfs-server | Aug 31, 2020 | Oct 31, 2018 |
| Redhat_linux | — | Upgrade glusterfs-server | Jun 14, 2019 | Oct 31, 2018 |
| Ubuntu | — | Upgrade glusterfs-server (Ubuntu Pro)Upgrade glusterfs-common (Ubuntu Pro)Upgrade glusterfs-client (Ubuntu Pro) | Mar 22, 2023 | Oct 31, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub