5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
8 High
AI Score
Confidence
High
0.004 Low
EPSS
Percentile
74.5%
Issue Overview:
A flaw was found in dict.c:dict_unserialize function of glusterfs, dic_unserialize function does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.(CVE-2018-10911)
Affected Packages:
glusterfs
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update glusterfs to update your system.
New Packages:
aarch64:
glusterfs-3.12.2-18.amzn2.aarch64
glusterfs-api-3.12.2-18.amzn2.aarch64
glusterfs-api-devel-3.12.2-18.amzn2.aarch64
glusterfs-cli-3.12.2-18.amzn2.aarch64
glusterfs-devel-3.12.2-18.amzn2.aarch64
glusterfs-fuse-3.12.2-18.amzn2.aarch64
glusterfs-libs-3.12.2-18.amzn2.aarch64
python2-gluster-3.12.2-18.amzn2.aarch64
glusterfs-rdma-3.12.2-18.amzn2.aarch64
glusterfs-client-xlators-3.12.2-18.amzn2.aarch64
glusterfs-debuginfo-3.12.2-18.amzn2.aarch64
i686:
glusterfs-3.12.2-18.amzn2.i686
glusterfs-api-3.12.2-18.amzn2.i686
glusterfs-api-devel-3.12.2-18.amzn2.i686
glusterfs-cli-3.12.2-18.amzn2.i686
glusterfs-devel-3.12.2-18.amzn2.i686
glusterfs-fuse-3.12.2-18.amzn2.i686
glusterfs-libs-3.12.2-18.amzn2.i686
python2-gluster-3.12.2-18.amzn2.i686
glusterfs-rdma-3.12.2-18.amzn2.i686
glusterfs-client-xlators-3.12.2-18.amzn2.i686
glusterfs-debuginfo-3.12.2-18.amzn2.i686
src:
glusterfs-3.12.2-18.amzn2.src
x86_64:
glusterfs-3.12.2-18.amzn2.x86_64
glusterfs-api-3.12.2-18.amzn2.x86_64
glusterfs-api-devel-3.12.2-18.amzn2.x86_64
glusterfs-cli-3.12.2-18.amzn2.x86_64
glusterfs-devel-3.12.2-18.amzn2.x86_64
glusterfs-fuse-3.12.2-18.amzn2.x86_64
glusterfs-libs-3.12.2-18.amzn2.x86_64
python2-gluster-3.12.2-18.amzn2.x86_64
glusterfs-rdma-3.12.2-18.amzn2.x86_64
glusterfs-client-xlators-3.12.2-18.amzn2.x86_64
glusterfs-debuginfo-3.12.2-18.amzn2.x86_64
Red Hat: CVE-2018-10911
Mitre: CVE-2018-10911
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Amazon Linux | 2 | aarch64 | glusterfs | < 3.12.2-18.amzn2 | glusterfs-3.12.2-18.amzn2.aarch64.rpm |
Amazon Linux | 2 | aarch64 | glusterfs-api | < 3.12.2-18.amzn2 | glusterfs-api-3.12.2-18.amzn2.aarch64.rpm |
Amazon Linux | 2 | aarch64 | glusterfs-api-devel | < 3.12.2-18.amzn2 | glusterfs-api-devel-3.12.2-18.amzn2.aarch64.rpm |
Amazon Linux | 2 | aarch64 | glusterfs-cli | < 3.12.2-18.amzn2 | glusterfs-cli-3.12.2-18.amzn2.aarch64.rpm |
Amazon Linux | 2 | aarch64 | glusterfs-devel | < 3.12.2-18.amzn2 | glusterfs-devel-3.12.2-18.amzn2.aarch64.rpm |
Amazon Linux | 2 | aarch64 | glusterfs-fuse | < 3.12.2-18.amzn2 | glusterfs-fuse-3.12.2-18.amzn2.aarch64.rpm |
Amazon Linux | 2 | aarch64 | glusterfs-libs | < 3.12.2-18.amzn2 | glusterfs-libs-3.12.2-18.amzn2.aarch64.rpm |
Amazon Linux | 2 | aarch64 | python2-gluster | < 3.12.2-18.amzn2 | python2-gluster-3.12.2-18.amzn2.aarch64.rpm |
Amazon Linux | 2 | aarch64 | glusterfs-rdma | < 3.12.2-18.amzn2 | glusterfs-rdma-3.12.2-18.amzn2.aarch64.rpm |
Amazon Linux | 2 | aarch64 | glusterfs-client-xlators | < 3.12.2-18.amzn2 | glusterfs-client-xlators-3.12.2-18.amzn2.aarch64.rpm |
5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
8 High
AI Score
Confidence
High
0.004 Low
EPSS
Percentile
74.5%