A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1510-1 | glusterfs security update |
Debian DLA |
DLA-2806-1 | glusterfs security update |
EUVD |
EUVD-2018-2967 | A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value. |
Ubuntu USN |
USN-4770-1 | GlusterFS vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T07:54:35.246Z
Reserved: 2018-05-09T00:00:00
Link: CVE-2018-10911
No data.
Status : Modified
Published: 2018-09-04T14:29:00.220
Modified: 2024-11-21T03:42:17.023
Link: CVE-2018-10911
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN