ZeroHour

CVE-2018-10911

CVSS 3.1
7.5 high
EPSS
3%p87
Published
()
Modified
Description

A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.

Vendors
glusterredhatdebianopensuse
Products
glusterfs, virtualization host, enterprise linux desktop, enterprise linux server, enterprise linux workstation, debian linux, leap
Weakness
CWE-190, CWE-200, CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.