Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13075
HistoryJan 15, 2019 - 9:25 a.m.

Symlink Attack

2019-01-1509:25:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.008 Low

EPSS

Percentile

81.4%

libglusterfs.so is vulnerable to a symlink attack. The library allows the use of the / character in basenames, allowing a malicious user to conduct a symlink attack to execute arbitrary code, create arbitrary files or crash the application. The vulnerability is due to an incomplete fix of CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926.