VYPR

Glusterfs

by Gluster

Source repositories

CVEs (28)

  • CVE-2018-10930MedSep 4, 2018
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.

  • CVE-2018-10914MedSep 4, 2018
    risk 0.42cvss 6.5epss 0.02

    It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.

  • CVE-2018-10913MedSep 4, 2018
    risk 0.42cvss 6.5epss 0.02

    An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.

  • CVE-2018-10924MedSep 4, 2018
    risk 0.35cvss 5.3epss 0.02

    It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.

  • CVE-2017-15096LowOct 26, 2017
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.

  • CVE-2014-3619Mar 27, 2015
    risk 0.00cvss epss 0.03

    The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.

  • CVE-2012-5635Apr 9, 2013
    risk 0.00cvss epss 0.00

    The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and…

  • CVE-2012-4417Nov 18, 2012
    risk 0.00cvss epss 0.00

    GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

Page 2 of 2