ALT-BU-2018-3511-1
Branch sisyphus update bulletin.
Package glusterfs3 updated to version 3.12.15-alt1 for branch sisyphus in task 214710.
Closed vulnerabilities
BDU:2019-00238
Уязвимость функции dic_unserialize файловой системы GlusterFS, позволяющая нарушителю получить доступ к защищаемой информации
Modified: 2024-11-21
CVE-2018-10904
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a gluster volume.
- openSUSE-SU-2020:0079
- openSUSE-SU-2020:0079
- RHSA-2018:2607
- RHSA-2018:2607
- RHSA-2018:2608
- RHSA-2018:2608
- RHSA-2018:3470
- RHSA-2018:3470
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10904
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10904
- [debian-lts-announce] 20180920 [SECURITY] [DLA 1510-1] glusterfs security update
- [debian-lts-announce] 20180920 [SECURITY] [DLA 1510-1] glusterfs security update
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- https://review.gluster.org/#/c/glusterfs/+/21072/
- https://review.gluster.org/#/c/glusterfs/+/21072/
- GLSA-201904-06
- GLSA-201904-06
Modified: 2024-11-21
CVE-2018-10907
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.
- openSUSE-SU-2020:0079
- openSUSE-SU-2020:0079
- RHSA-2018:2607
- RHSA-2018:2607
- RHSA-2018:2608
- RHSA-2018:2608
- RHSA-2018:3470
- RHSA-2018:3470
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10907
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10907
- [debian-lts-announce] 20180920 [SECURITY] [DLA 1510-1] glusterfs security update
- [debian-lts-announce] 20180920 [SECURITY] [DLA 1510-1] glusterfs security update
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- https://review.gluster.org/#/c/glusterfs/+/21070/
- https://review.gluster.org/#/c/glusterfs/+/21070/
- GLSA-201904-06
- GLSA-201904-06
Modified: 2024-11-21
CVE-2018-10911
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
- openSUSE-SU-2020:0079
- openSUSE-SU-2020:0079
- RHSA-2018:2607
- RHSA-2018:2607
- RHSA-2018:2608
- RHSA-2018:2608
- RHSA-2018:2892
- RHSA-2018:2892
- RHSA-2018:3242
- RHSA-2018:3242
- RHSA-2018:3470
- RHSA-2018:3470
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10911
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10911
- [debian-lts-announce] 20180920 [SECURITY] [DLA 1510-1] glusterfs security update
- [debian-lts-announce] 20180920 [SECURITY] [DLA 1510-1] glusterfs security update
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- https://review.gluster.org/#/c/glusterfs/+/21067/
- https://review.gluster.org/#/c/glusterfs/+/21067/
- GLSA-201904-06
- GLSA-201904-06
Modified: 2024-11-21
CVE-2018-10913
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.
- openSUSE-SU-2020:0079
- openSUSE-SU-2020:0079
- RHSA-2018:2607
- RHSA-2018:2607
- RHSA-2018:2608
- RHSA-2018:2608
- RHSA-2018:3470
- RHSA-2018:3470
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10913
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10913
- [debian-lts-announce] 20180920 [SECURITY] [DLA 1510-1] glusterfs security update
- [debian-lts-announce] 20180920 [SECURITY] [DLA 1510-1] glusterfs security update
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- https://review.gluster.org/#/c/glusterfs/+/21071/
- https://review.gluster.org/#/c/glusterfs/+/21071/
- GLSA-201904-06
- GLSA-201904-06
Modified: 2024-11-21
CVE-2018-10923
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.
- openSUSE-SU-2020:0079
- openSUSE-SU-2020:0079
- RHSA-2018:2607
- RHSA-2018:2607
- RHSA-2018:2608
- RHSA-2018:2608
- RHSA-2018:3470
- RHSA-2018:3470
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10923
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10923
- [debian-lts-announce] 20180920 [SECURITY] [DLA 1510-1] glusterfs security update
- [debian-lts-announce] 20180920 [SECURITY] [DLA 1510-1] glusterfs security update
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- GLSA-201904-06
- GLSA-201904-06
Modified: 2024-11-21
CVE-2018-10930
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.
- openSUSE-SU-2020:0079
- openSUSE-SU-2020:0079
- RHSA-2018:2607
- RHSA-2018:2607
- RHSA-2018:2608
- RHSA-2018:2608
- RHSA-2018:3470
- RHSA-2018:3470
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10930
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10930
- [debian-lts-announce] 20180920 [SECURITY] [DLA 1510-1] glusterfs security update
- [debian-lts-announce] 20180920 [SECURITY] [DLA 1510-1] glusterfs security update
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- https://review.gluster.org/#/c/glusterfs/+/21068/
- https://review.gluster.org/#/c/glusterfs/+/21068/
- GLSA-201904-06
- GLSA-201904-06