CVE Vulnerabilities

CVE-2014-3619

Published: Mar 27, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a 00000000 fragment header.

Affected Software

NameVendorStart VersionEnd Version
OpensuseOpensuse13.1 (including)13.1 (including)
Native Client for RHEL 5 for Red Hat StorageRedHatglusterfs-0:3.6.0.42-1.el5*
Native Client for RHEL 6 for Red Hat StorageRedHatglusterfs-0:3.6.0.42-1.el6*
Red Hat Common for RHEL 7RedHatglusterfs-0:3.6.0.42-1.el7*
Red Hat Storage 3 for RHEL 6RedHatglusterfs-0:3.6.0.42-1.el6rhs*
Red Hat Storage 3 for RHEL 6RedHatgluster-nagios-addons-0:0.1.14-1.el6rhs*
Red Hat Storage 3 for RHEL 6RedHatgluster-nagios-common-0:0.1.4-1.el6rhs*
Red Hat Storage 3 for RHEL 6RedHatgstatus-0:0.62-1.el6rhs*
Red Hat Storage 3 for RHEL 6RedHatopenstack-swift-0:1.13.1-2.el6ost*
Red Hat Storage 3 for RHEL 6RedHatopenstack-swift-plugin-swift3-0:1.7-3.el6ost*
Red Hat Storage 3 for RHEL 6RedHatpython-paste-deploy-0:1.5.0-10.el6ost*
Red Hat Storage 3 for RHEL 6RedHatpython-swiftclient-0:2.1.0-2.el6ost*
Red Hat Storage 3 for RHEL 6RedHatredhat-storage-server-0:3.0.3.4-1.el6rhs*
Red Hat Storage 3 for RHEL 6RedHatsamba-0:3.6.509-169.4.el6rhs*
Red Hat Storage 3 for RHEL 6RedHatswiftonfile-0:1.13.1-2.el6rhs*
Red Hat Storage 3 for RHEL 6RedHatvdsm-0:4.14.7.3-1.el6rhs*
GlusterfsUbuntuesm-infra-legacy/trusty*
GlusterfsUbuntulucid*
GlusterfsUbuntuprecise*
GlusterfsUbuntutrusty*
GlusterfsUbuntutrusty/esm*
GlusterfsUbuntuupstream*
GlusterfsUbuntuutopic*

References