It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execute arbitrary code, create arbitrary files, or cause denial of service on glusterfs server nodes via symlinks to relative paths.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2018:3431 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2018:3432 | Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14651 | Issue Tracking Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2018/11/msg00003.html | Third Party Advisory |
https://security.gentoo.org/glsa/201904-06 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2018-10-31T21:00:00
Updated: 2019-04-02T06:06:05
Reserved: 2018-07-27T00:00:00
Link: CVE-2018-14651
JSON object: View
NVD Information
Status : Modified
Published: 2018-10-31T22:29:00.353
Modified: 2023-02-12T23:32:26.993
Link: CVE-2018-14651
JSON object: View
Redhat Information
No data.
CWE