CVE-2018-14653: Buffer Overflow
The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the 'servergetspec' function via the 'gfgetspecreq' RPC message. A remote authenticated attacker could exploit this to cause a denial of service or other potential unspecified impact.
Other sources
The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the "servergetspec" function via the "gfgetspecreq" RPC message. A remote authenticated attacker could exploit this to cause a denial of service or other potential unspecified impact.
Patching this issue also requires fixing the "buildvolfilepath" function to prevent arbitrary file reads via crafted filenames.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-14653?
CVE-2018-14653 is a vulnerability found in the Gluster file system through versions 4.1.4 and 3.12.
What is the severity of CVE-2018-14653?
CVE-2018-14653 has a severity score of 8.8 (high).
Who is affected by CVE-2018-14653?
Users of Redhat Gluster Storage versions 3.0.0 to 3.1.2 and 4.1.0 to 4.1.4, Debian Linux versions 8.0 and 9.0, and Redhat Enterprise Linux Server version 6.0 and 7.0, as well as Redhat Enterprise Linux Virtualization version 4.0, are affected by CVE-2018-14653.
How can CVE-2018-14653 be exploited?
CVE-2018-14653 can be exploited by a remote authenticated attacker through a heap-based buffer overflow in the '__server_getspec' function using the 'gf_getspec_req' RPC message.
What is the impact of CVE-2018-14653?
The impact of CVE-2018-14653 is a denial of service or potential unspecified impact.