CVE-2014-3619: Medium severity opensuse vulnerability
IssueDescription:
A denial of service flaw was found in the way the socketprotostatemachine() function of glusterfs processed certain fragment headers. A remote attacker could send a specially crafted fragment header that, when processed, would cause the glusterfs process to enter an infinite loop.
Other sources
The socketprotostatemachine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3619?
CVE-2014-3619 is classified as a denial of service vulnerability.
How do I fix CVE-2014-3619?
To mitigate CVE-2014-3619, upgrade to a patched version of GlusterFS or openSUSE.
Which versions are affected by CVE-2014-3619?
CVE-2014-3619 affects GlusterFS version 3.5 and openSUSE version 13.1.
Can CVE-2014-3619 be exploited remotely?
Yes, CVE-2014-3619 can be exploited remotely by sending specially crafted fragment headers.
What would an attacker gain by exploiting CVE-2014-3619?
An attacker exploiting CVE-2014-3619 could cause the GlusterFS process to enter an infinite loop, leading to denial of service.