Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.882960
Category:CentOS Local Security Checks
Title:CentOS Update for glusterfs CESA-2018:2892 centos6
Summary:Check the version of glusterfs
Description:Summary:
Check the version of glusterfs

Vulnerability Insight:
GlusterFS is a key building block of Red Hat
Gluster Storage. It is based on a stackable user-space design and can deliver
exceptional performance for diverse workloads. GlusterFS aggregates various
storage servers over network interconnections into one large, parallel network
file system.

The glusterfs packages have been upgraded to upstream version 3.12.2, which
provides a number of bug fixes over the previous version. (BZ#1594203)

Security Fix(es):

* glusterfs: Improper deserialization in dict.c:dict_unserialize() can
allow attackers to read arbitrary memory (CVE-2018-10911)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

Red Hat would like to thank Michael Hanselmann (hansmi.ch) for reporting
this issue.

Affected Software/OS:
glusterfs on CentOS 6

Solution:
Please install the updated packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-10911
https://security.gentoo.org/glsa/201904-06
https://lists.debian.org/debian-lts-announce/2018/09/msg00021.html
https://lists.debian.org/debian-lts-announce/2021/11/msg00000.html
RedHat Security Advisories: RHSA-2018:2607
https://access.redhat.com/errata/RHSA-2018:2607
RedHat Security Advisories: RHSA-2018:2608
https://access.redhat.com/errata/RHSA-2018:2608
RedHat Security Advisories: RHSA-2018:2892
https://access.redhat.com/errata/RHSA-2018:2892
RedHat Security Advisories: RHSA-2018:3242
https://access.redhat.com/errata/RHSA-2018:3242
RedHat Security Advisories: RHSA-2018:3470
https://access.redhat.com/errata/RHSA-2018:3470
SuSE Security Announcement: openSUSE-SU-2020:0079 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.html
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.