Wind River Support Network

HomeDefectsLIN8-9786
Fixed

LIN8-9786 : Security Advisory - glusterfs - CVE-2018-10904

Created: Sep 17, 2018    Updated: Dec 21, 2018
Resolved Date: Oct 9, 2018
Found In Version: 8.0.0.27
Fix Version: 8.0.0.28
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

It was found that glusterfs server does not properly sanitize file paths in the trusted.io-stats-dump extended attribute which is used by the debug/io-stats translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a gluster volume.

https://nvd.nist.gov/vuln/detail/CVE-2018-10904

Other Downloads


CVEs


Live chat
Online