Security Advisory

CVE-2018-10907

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-09-04 13:00:00
Last updated 2024-08-05 07:54:34
Assigner redhat
State PUBLISHED

Description

It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using alloca(3). An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.