7.5
CVSSv3

CVE-2018-10911

Published: 04/09/2018 Updated: 22/04/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gluster glusterfs

redhat virtualization host 4.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux desktop 7.0

redhat enterprise linux desktop 6.0

redhat enterprise linux server 7.0

redhat enterprise linux workstation 7.0

debian debian linux 8.0

debian debian linux 9.0

opensuse leap 15.1

Vendor Advisories

Debian Bug report logs - #909215 glusterfs: Multiple security issues Package: glusterfs; Maintainer for glusterfs is Patrick Matthäi <pmatthaei@debianorg>; Reported by: Markus Koschany <apo@debianorg> Date: Wed, 19 Sep 2018 19:54:01 UTC Severity: grave Tags: security, upstream Found in versions 413-1, 388-1 F ...
Synopsis Important: Red Hat Gluster Storage security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic Updated glusterfs packages that fix multiple security issues, several bugs, and adds various enhancements are now available for Red Hat Gluster Storage 34 on Red Hat Enterp ...
Synopsis Moderate: glusterfs security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for glusterfs is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scorin ...
Synopsis Moderate: glusterfs security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for glusterfs is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scorin ...
Synopsis Important: Red Hat Gluster Storage security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic Updated glusterfs packages that fix multiple security issues and bugs, and add various enhancements are now available for Red Hat Gluster Storage 34 on Red Hat Enterprise L ...
Synopsis Moderate: Red Hat Virtualization security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for imgbased, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Red Hat Product Securi ...
A flaw was found in dictc:dict_unserialize function of glusterfs, dic_unserialize function does not handle negative key length values An attacker could use this flaw to read memory from other locations into the stored dict value(CVE-2018-10911) ...
A flaw was found in dictc:dict_unserialize function of glusterfs, dic_unserialize function does not handle negative key length values An attacker could use this flaw to read memory from other locations into the stored dict value ...