Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7676
HistoryNov 01, 2018 - 8:59 a.m.

Symlink Attack

2018-11-0108:59:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.008 Low

EPSS

Percentile

81.4%

libglusterfs.so is vulnerable to a symlink attack. The library allows the use of the / character in basenames, allowing a malicious user to conduct a symlink attack to execute arbitrary code, create arbitrary files or crash the application. The vulnerability is due to an incomplete fix of CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926.