![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2018-14654 |
Description: | The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2018-14654 GLSA-201904-06 https://security.gentoo.org/glsa/201904-06 RHSA-2018:3431 https://access.redhat.com/errata/RHSA-2018:3431 RHSA-2018:3432 https://access.redhat.com/errata/RHSA-2018:3432 RHSA-2018:3470 https://access.redhat.com/errata/RHSA-2018:3470 [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update https://lists.debian.org/debian-lts-announce/2021/11/msg00000.html https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14654 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14654 |