CVE-2018-14654
31.10.2018, 19:29
The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server.
Vendor | Product | Version |
---|---|---|
redhat | gluster_storage | 𝑥 ≤ 4.1.4 |
redhat | enterprise_linux_server | 6.0 |
redhat | enterprise_linux_server | 7.0 |
redhat | enterprise_linux_virtualization | 4.0 |
redhat | virtualization | 4.0 |
redhat | virtualization_host | 4.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References