Vulnerability Description
The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_getspec_req' RPC message. A remote authenticated attacker could exploit this to cause a denial of service or other potential unspecified impact.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Gluster Storage | >= 3.0.0, <= 3.1.2 |
| Debian | Debian Linux | 8.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Virtualization | 4.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2018:3431Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3432Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3470Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14653Issue TrackingVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/11/msg00003.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201904-06Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3431Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3432Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3470Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14653Issue TrackingVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/11/msg00003.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201904-06Third Party Advisory
FAQ
What is CVE-2018-14653?
CVE-2018-14653 is a vulnerability with a CVSS score of 8.8 (HIGH). The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_getspec_req' RPC message. A remote authenticated at...
How severe is CVE-2018-14653?
CVE-2018-14653 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-14653?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Gluster Storage, Debian Debian Linux, Redhat Enterprise Linux Server, Redhat Enterprise Linux Virtualization.