CVE-2018-14661: Input Validation
A vulnerability was found in Gluster's features/locks translator An user-controlled string is given to snprintf without a proper format string. Sending a specially crafted string would result in a denial of service.
Other sources
It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker could use this flaw to cause remote denial of service.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-14661?
CVE-2018-14661 is a vulnerability found in the glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, which allows a remote authenticated attacker to cause remote denial of service.
How severe is CVE-2018-14661?
CVE-2018-14661 has a severity score of 6.5 out of 10.
What is the affected software of CVE-2018-14661?
The affected software includes glusterfs server 3.8.4, Debian Linux 8.0 and 9.0, Red Hat Virtualization 4.0 and Red Hat Virtualization Host 4.0.
How can I fix CVE-2018-14661?
To fix CVE-2018-14661, it is recommended to update to a patched version of glusterfs server and follow the instructions provided by the vendor.
Where can I find more information about CVE-2018-14661?
You can find more information about CVE-2018-14661 on the Red Hat Bugzilla and Red Hat Security Advisories websites.