High severity7.5NVD Advisory· Published Jun 10, 2018· Updated Jun 17, 2026
CVE-2018-12088
CVE-2018-12088
Description
S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files, or temporarily hide parts of files. This is related to the checksum_basic_mapping function.
Affected products
3Patches
Vulnerability mechanics
References
3- bitbucket.org/nikratio/s3ql/commits/85aba5c2d5c81453a73a50ed638adaeef0521020nvdPatchThird Party Advisory
- bitbucket.org/nikratio/s3ql/issues/272/t3_verifypy-test_retrieve-sometimes-failsnvdExploitThird Party Advisory
- groups.google.com/forum/nvd
News mentions
0No linked articles in our index yet.