Gentoo Archives: gentoo-announce

From: Aaron Bauman <bman@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201904-06 ] GlusterFS: Multiple Vulnerabilities
Date: Tue, 02 Apr 2019 04:50:12
Message-Id: 20190402042743.GF29674@monkey
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201904-06
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: GlusterFS: Multiple Vulnerabilities
9 Date: April 02, 2019
10 Bugs: #653070, #658606, #664336, #670088
11 ID: 201904-06
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in GlusterFS, the worst of
19 which could result in the execution of arbitrary code.
20
21 Background
22 ==========
23
24 A free and open source software scalable network filesystem.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 sys-cluster/glusterfs < 4.1.8 >= 4.1.8
33
34 Description
35 ===========
36
37 Multiple vulnerabilities have been discovered in GlusterFS. Please
38 review the referenced CVE identifiers for details.
39
40 Impact
41 ======
42
43 Please review the referenced CVE identifiers for details.
44
45 Workaround
46 ==========
47
48 There is no known workaround at this time.
49
50 Resolution
51 ==========
52
53 All GlusterFS users should upgrade to the latest version:
54
55 # emerge --sync
56 # emerge --ask --oneshot --verbose ">=sys-cluster/glusterfs-4.1.8"
57
58 References
59 ==========
60
61 [ 1 ] CVE-2018-10841
62 https://nvd.nist.gov/vuln/detail/CVE-2018-10841
63 [ 2 ] CVE-2018-1088
64 https://nvd.nist.gov/vuln/detail/CVE-2018-1088
65 [ 3 ] CVE-2018-10904
66 https://nvd.nist.gov/vuln/detail/CVE-2018-10904
67 [ 4 ] CVE-2018-10907
68 https://nvd.nist.gov/vuln/detail/CVE-2018-10907
69 [ 5 ] CVE-2018-10911
70 https://nvd.nist.gov/vuln/detail/CVE-2018-10911
71 [ 6 ] CVE-2018-10913
72 https://nvd.nist.gov/vuln/detail/CVE-2018-10913
73 [ 7 ] CVE-2018-10914
74 https://nvd.nist.gov/vuln/detail/CVE-2018-10914
75 [ 8 ] CVE-2018-10923
76 https://nvd.nist.gov/vuln/detail/CVE-2018-10923
77 [ 9 ] CVE-2018-10924
78 https://nvd.nist.gov/vuln/detail/CVE-2018-10924
79 [ 10 ] CVE-2018-10926
80 https://nvd.nist.gov/vuln/detail/CVE-2018-10926
81 [ 11 ] CVE-2018-10927
82 https://nvd.nist.gov/vuln/detail/CVE-2018-10927
83 [ 12 ] CVE-2018-10928
84 https://nvd.nist.gov/vuln/detail/CVE-2018-10928
85 [ 13 ] CVE-2018-10929
86 https://nvd.nist.gov/vuln/detail/CVE-2018-10929
87 [ 14 ] CVE-2018-10930
88 https://nvd.nist.gov/vuln/detail/CVE-2018-10930
89 [ 15 ] CVE-2018-14651
90 https://nvd.nist.gov/vuln/detail/CVE-2018-14651
91 [ 16 ] CVE-2018-14652
92 https://nvd.nist.gov/vuln/detail/CVE-2018-14652
93 [ 17 ] CVE-2018-14653
94 https://nvd.nist.gov/vuln/detail/CVE-2018-14653
95 [ 18 ] CVE-2018-14654
96 https://nvd.nist.gov/vuln/detail/CVE-2018-14654
97 [ 19 ] CVE-2018-14659
98 https://nvd.nist.gov/vuln/detail/CVE-2018-14659
99 [ 20 ] CVE-2018-14660
100 https://nvd.nist.gov/vuln/detail/CVE-2018-14660
101 [ 21 ] CVE-2018-14661
102 https://nvd.nist.gov/vuln/detail/CVE-2018-14661
103
104 Availability
105 ============
106
107 This GLSA and any updates to it are available for viewing at
108 the Gentoo Security Website:
109
110 https://security.gentoo.org/glsa/201904-06
111
112 Concerns?
113 =========
114
115 Security is a primary focus of Gentoo Linux and ensuring the
116 confidentiality and security of our users' machines is of utmost
117 importance to us. Any security concerns should be addressed to
118 security@g.o or alternatively, you may file a bug at
119 https://bugs.gentoo.org.
120
121 License
122 =======
123
124 Copyright 2019 Gentoo Foundation, Inc; referenced text
125 belongs to its owner(s).
126
127 The contents of this document are licensed under the
128 Creative Commons - Attribution / Share Alike license.
129
130 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature