6.5

CVE-2018-14661

It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker could use this flaw to cause remote denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gluster ≫ Glusterfs Version 3.8.4
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Redhat ≫ Virtualization Version 4.0
   Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Virtualization Host Version 4.0
   Redhat ≫ Enterprise Linux Version 7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.66% 0.837
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://lists.debian.org/debian-lts-announce/2021/11/msg00000.html
Third Party Advisory
Mailing List
https://security.gentoo.org/glsa/201904-06
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3470
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3431
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3432
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/11/msg00003.html
Third Party Advisory
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14661
Third Party Advisory
Issue Tracking