CVE Published: 04/09/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: redhat |
Vendor: Red Hat |
Product: glusterfs Status : PUBLISHED
CVE-2018-10907 Description
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using \'alloca(3)\'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.