CVE-2018-14659

Source
https://cve.org/CVERecord?id=CVE-2018-14659
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-14659.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-14659
Downstream
Published
2018-10-31T19:29:00.627Z
Modified
2026-02-17T07:08:34.652614Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GFXATTRIOSTATSDUMPKEY' xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling 'setxattr(2)' to trigger a state dump and create an arbitrary number of files in the server's runtime directory.

References

Affected packages

Git / git.savannah.nongnu.org/git/libtasn1.git/

Affected ranges

Type
GIT
Repo
http://git.savannah.nongnu.org/git/libtasn1.git/
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
d2521ee04e00e1c060001d5d67c1cf0bd23ec260

Affected versions

Other
gnutls_0_5_0
gnutls_0_5_1
libasn1_0_1_0
libtasn1-0-3-2
libtasn1_0_1_2
libtasn1_0_2_0
libtasn1_0_2_1
libtasn1_0_2_10
libtasn1_0_2_11
libtasn1_0_2_12
libtasn1_0_2_13
libtasn1_0_2_14
libtasn1_0_2_15
libtasn1_0_2_16
libtasn1_0_2_17
libtasn1_0_2_18
libtasn1_0_2_2
libtasn1_0_2_3
libtasn1_0_2_4
libtasn1_0_2_5
libtasn1_0_2_6
libtasn1_0_2_7
libtasn1_0_2_8
libtasn1_0_2_9
libtasn1_0_3_0
libtasn1_0_3_1
libtasn1_0_3_10
libtasn1_0_3_2
libtasn1_0_3_3
libtasn1_0_3_4
libtasn1_0_3_5
libtasn1_0_3_6
libtasn1_0_3_7
libtasn1_0_3_8
libtasn1_0_3_9
libtasn1_1_0
libtasn1_1_1
libtasn1_1_2
libtasn1_1_3
libtasn1_1_4
libtasn1_1_5
libtasn1_1_6
libtasn1_2_0
libtasn1_2_1
libtasn1_2_10
libtasn1_2_11
libtasn1_2_12
libtasn1_2_13
libtasn1_2_2
libtasn1_2_3
libtasn1_2_4
libtasn1_2_5
libtasn1_2_6
libtasn1_2_7
libtasn1_2_8
libtasn1_2_9
libtasn1_3_0
libtasn1_3_1
libtasn1_3_2
libtasn1_3_3
libtasn1_3_4
libtasn1_3_5
libtasn1_3_6
libtasn1_4_0
libtasn1_after_rename

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-14659.json"