Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.12.2021.4770.1
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-4770-1)
Summary:The remote host is missing an update for the 'glusterfs' package(s) announced via the USN-4770-1 advisory.
Description:Summary:
The remote host is missing an update for the 'glusterfs' package(s) announced via the USN-4770-1 advisory.

Vulnerability Insight:
It was discovered that GlusterFS incorrectly handled network requests. An
attacker could possibly use this issue to cause a denial of service. This issue
only affected Ubuntu 14.04 ESM. (CVE-2014-3619)

It was discovered that GlusterFS incorrectly handled user permissions. An
authenticated attacker could possibly use this to add himself to a trusted
storage pool and perform privileged operations on volumes. This issue only
affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-10841)

It was discovered that GlusterFS incorrectly handled mounting gluster
volumes. An attacker could possibly use this issue to also mount shared
gluster volumes and escalate privileges through malicious cronjobs. This
issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-1088)

It was discovered that GlusterFS incorrectly handled file paths. An
attacker could possibly use this issue to create arbitrary files and
execute arbitrary code. (CVE-2018-10904)

It was discovered that GlusterFS incorrectly handled mounting volumes. An
attacker could possibly use this issue to cause a denial of service or run
arbitrary code. (CVE-2018-10907)

It was discovered that GlusterFS incorrectly handled negative key length
values. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2018-10911)

It was discovered that GlusterFS incorrectly handled FUSE requests. An
attacker could use this issue to obtain sensitive information.
(CVE-2018-10913, CVE-2018-10914)

It was discovered that GlusterFS incorrectly handled the file creation
process. An authenticated attacker could possibly use this issue to create
arbitrary files and obtain sensitive information. (CVE-2018-10923)

It was discovered that GlusterFS incorrectly handled certain inputs. An
authenticated attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 18.04 ESM. (CVE-2018-10924)

It was discovered that GlusterFS incorrectly handled RPC requests. An
attacker could possibly use this issue to write files to an arbitrary
location and execute arbitrary code. (CVE-2018-10926, CVE-2018-10927,
CVE-2018-10928, CVE-2018-10929, CVE-2018-10930)

It was discovered that the fix for CVE-2018-10926, CVE-2018-10927,
CVE-2018-10928, CVE-2018-10929, CVE-2018-10930 was incomplete. A remote
authenticated attacker could possibly use this issue to execute arbitrary
code or cause a denial of service. (CVE-2018-14651)

It was discovered that GlusterFS incorrectly handled certain files. A
remote authenticated attacker could possibly use this issue to cause a
denial of service. (CVE-2018-14652)

It was discovered that GlusterFS incorrectly handled RPC requests. A remote
authenticated attacker could possibly use this issue to cause a denial of
service or other unspecified impact. (CVE-2018-14653)

It was discovered that GlusterFS incorrectly handled mount volumes
operation. A remote attacker ... [Please see the references for more information on the vulnerabilities]

Affected Software/OS:
'glusterfs' package(s) on Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04.

Solution:
Please install the updated package(s).

CVSS Score:
8.5

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-3619
MDVSA-2015:211
http://www.mandriva.com/security/advisories?name=MDVSA-2015:211
http://advisories.mageia.org/MGASA-2015-0145.html
http://review.gluster.org/#/c/8662/4
https://bugzilla.redhat.com/show_bug.cgi?id=1138145
openSUSE-SU-2015:0473
http://lists.opensuse.org/opensuse-updates/2015-03/msg00031.html
openSUSE-SU-2015:0528
http://lists.opensuse.org/opensuse-updates/2015-03/msg00056.html
Common Vulnerability Exposure (CVE) ID: CVE-2018-10841
GLSA-201904-06
https://security.gentoo.org/glsa/201904-06
RHSA-2018:1954
https://access.redhat.com/errata/RHSA-2018:1954
RHSA-2018:1955
https://access.redhat.com/errata/RHSA-2018:1955
[debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
https://lists.debian.org/debian-lts-announce/2021/11/msg00000.html
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10841
https://review.gluster.org/#/c/20328/
Common Vulnerability Exposure (CVE) ID: CVE-2018-1088
RHSA-2018:1136
https://access.redhat.com/errata/RHSA-2018:1136
RHSA-2018:1137
https://access.redhat.com/errata/RHSA-2018:1137
RHSA-2018:1275
https://access.redhat.com/errata/RHSA-2018:1275
RHSA-2018:1524
https://access.redhat.com/errata/RHSA-2018:1524
https://bugzilla.redhat.com/show_bug.cgi?id=1558721
openSUSE-SU-2020:0079
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.html
Common Vulnerability Exposure (CVE) ID: CVE-2018-10904
https://lists.debian.org/debian-lts-announce/2018/09/msg00021.html
RedHat Security Advisories: RHSA-2018:2607
https://access.redhat.com/errata/RHSA-2018:2607
RedHat Security Advisories: RHSA-2018:2608
https://access.redhat.com/errata/RHSA-2018:2608
RedHat Security Advisories: RHSA-2018:3470
https://access.redhat.com/errata/RHSA-2018:3470
SuSE Security Announcement: openSUSE-SU-2020:0079 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2018-10907
Common Vulnerability Exposure (CVE) ID: CVE-2018-10911
RedHat Security Advisories: RHSA-2018:2892
https://access.redhat.com/errata/RHSA-2018:2892
RedHat Security Advisories: RHSA-2018:3242
https://access.redhat.com/errata/RHSA-2018:3242
Common Vulnerability Exposure (CVE) ID: CVE-2018-10913
Common Vulnerability Exposure (CVE) ID: CVE-2018-10914
Common Vulnerability Exposure (CVE) ID: CVE-2018-10923
Common Vulnerability Exposure (CVE) ID: CVE-2018-10924
Common Vulnerability Exposure (CVE) ID: CVE-2018-10926
Common Vulnerability Exposure (CVE) ID: CVE-2018-10927
Common Vulnerability Exposure (CVE) ID: CVE-2018-10928
Common Vulnerability Exposure (CVE) ID: CVE-2018-10929
BugTraq ID: 107577
http://www.securityfocus.com/bid/107577
Common Vulnerability Exposure (CVE) ID: CVE-2018-10930
Common Vulnerability Exposure (CVE) ID: CVE-2018-14651
RHSA-2018:3431
https://access.redhat.com/errata/RHSA-2018:3431
RHSA-2018:3432
https://access.redhat.com/errata/RHSA-2018:3432
[debian-lts-announce] 20181105 [SECURITY] [DLA 1565-1] glusterfs security update
https://lists.debian.org/debian-lts-announce/2018/11/msg00003.html
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14651
Common Vulnerability Exposure (CVE) ID: CVE-2018-14652
RHSA-2018:3470
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14652
Common Vulnerability Exposure (CVE) ID: CVE-2018-14653
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14653
Common Vulnerability Exposure (CVE) ID: CVE-2018-14654
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14654
Common Vulnerability Exposure (CVE) ID: CVE-2018-14659
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14659
Common Vulnerability Exposure (CVE) ID: CVE-2018-14660
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14660
Common Vulnerability Exposure (CVE) ID: CVE-2018-14661
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14661
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.