Flaw in GlusterFS Allows Memory Read Vulnerability
CVE-2018-10911
6.5MEDIUM
Summary
A flaw exists in the 'dic_unserialize' function of GlusterFS where negative key length values are not properly handled. This oversight permits an attacker to manipulate the system and read memory from unintended locations, exposing sensitive information stored in the dictionary values. This vulnerability underscores the importance of secure handling of input values and the necessity for thorough validation in code.
Affected Version(s)
glusterfs:
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved