CVE-2018-10914
- EPSS 3.87%
- Veröffentlicht 04.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks an...
CVE-2018-10911
- EPSS 4.26%
- Veröffentlicht 04.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
CVE-2018-10913
- EPSS 0.94%
- Veröffentlicht 04.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.
CVE-2018-10923
- EPSS 0.91%
- Veröffentlicht 04.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:18
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs s...
CVE-2018-10907
- EPSS 2.11%
- Veröffentlicht 04.09.2018 13:29:11
- Zuletzt bearbeitet 21.11.2024 03:42:16
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume...
CVE-2018-10904
- EPSS 1.26%
- Veröffentlicht 04.09.2018 13:29:09
- Zuletzt bearbeitet 21.11.2024 03:42:16
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exp...
CVE-2018-10858
- EPSS 7.56%
- Veröffentlicht 22.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:09
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and ...
CVE-2018-10873
- EPSS 1.27%
- Veröffentlicht 17.08.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:11
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its p...
CVE-2018-10875
- EPSS 0.06%
- Veröffentlicht 13.07.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:11
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.
CVE-2018-10874
- EPSS 0.06%
- Veröffentlicht 02.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:11
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.