Redhat

Virtualization Host

84 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.87%
  • Veröffentlicht 04.09.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:17

It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks an...

  • EPSS 4.26%
  • Veröffentlicht 04.09.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:17

A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.

  • EPSS 0.94%
  • Veröffentlicht 04.09.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:17

An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.

  • EPSS 0.91%
  • Veröffentlicht 04.09.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:18

It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs s...

  • EPSS 2.11%
  • Veröffentlicht 04.09.2018 13:29:11
  • Zuletzt bearbeitet 21.11.2024 03:42:16

It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume...

  • EPSS 1.26%
  • Veröffentlicht 04.09.2018 13:29:09
  • Zuletzt bearbeitet 21.11.2024 03:42:16

It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exp...

  • EPSS 7.56%
  • Veröffentlicht 22.08.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:09

A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and ...

  • EPSS 1.27%
  • Veröffentlicht 17.08.2018 12:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:11

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its p...

  • EPSS 0.06%
  • Veröffentlicht 13.07.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:11

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

  • EPSS 0.06%
  • Veröffentlicht 02.07.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:11

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.