Bug 919879 (CVE-2014-3619) - VUL-0: CVE-2014-3619: glusterfs: fragment header infinite loop DoS
Summary: VUL-0: CVE-2014-3619: glusterfs: fragment header infinite loop DoS
Status: RESOLVED FIXED
Alias: CVE-2014-3619
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Jan Engelhardt
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/114300/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-02-27 08:11 UTC by Johannes Segitz
Modified: 2015-03-27 20:54 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2015-02-27 08:11:15 UTC
rh#1138145

A denial of service flaw was found in the way the __socket_proto_state_machine() function of glusterfs processed certain fragment headers. A remote attacker could send a specially crafted fragment header that, when processed, would cause the glusterfs process to enter an infinite loop.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1138145
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3619
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3619
Comment 1 Bernhard Wiedemann 2015-02-27 12:00:09 UTC
This is an autogenerated message for OBS integration:
This bug (919879) was mentioned in
https://build.opensuse.org/request/show/288068 13.1 / glusterfs
Comment 2 Swamp Workflow Management 2015-02-27 23:00:13 UTC
bugbot adjusting priority
Comment 3 Swamp Workflow Management 2015-03-11 12:05:23 UTC
openSUSE-SU-2015:0473-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 919879
CVE References: CVE-2014-3619
Sources used:
openSUSE 13.1 (src):    glusterfs-3.4.0~qa9-2.4.1
Comment 4 Andreas Stieger 2015-03-11 12:23:28 UTC
Hello, the patch is missing from the 13.2 package and applies there. If glusterof 3.5.2 in openSUSE 13.2 is affected, could you please submit an update?
Comment 5 Bernhard Wiedemann 2015-03-11 13:00:07 UTC
This is an autogenerated message for OBS integration:
This bug (919879) was mentioned in
https://build.opensuse.org/request/show/290294 13.2 / glusterfs
Comment 6 Swamp Workflow Management 2015-03-18 17:08:12 UTC
openSUSE-SU-2015:0528-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 919879
CVE References: CVE-2014-3619
Sources used:
openSUSE 13.2 (src):    glusterfs-3.5.2-2.4.1
Comment 7 Jan Engelhardt 2015-03-27 20:54:29 UTC
Update was sent out.