S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files, or temporarily hide parts of files. This is related to the checksum_basic_mapping function.
References
Link | Resource |
---|---|
https://bitbucket.org/nikratio/s3ql/commits/85aba5c2d5c81453a73a50ed638adaeef0521020 | Patch Third Party Advisory |
https://bitbucket.org/nikratio/s3ql/issues/272/t3_verifypy-test_retrieve-sometimes-fails | Exploit Third Party Advisory |
https://groups.google.com/forum/#%21topic/s3ql/4TzCVIMkA4o | |
https://bitbucket.org/nikratio/s3ql/commits/85aba5c2d5c81453a73a50ed638adaeef0521020 | Patch Third Party Advisory |
https://bitbucket.org/nikratio/s3ql/issues/272/t3_verifypy-test_retrieve-sometimes-fails | Exploit Third Party Advisory |
https://groups.google.com/forum/#%21topic/s3ql/4TzCVIMkA4o |
Configurations
History
21 Nov 2024, 03:44
Type | Values Removed | Values Added |
---|---|---|
References | () https://bitbucket.org/nikratio/s3ql/commits/85aba5c2d5c81453a73a50ed638adaeef0521020 - Patch, Third Party Advisory | |
References | () https://bitbucket.org/nikratio/s3ql/issues/272/t3_verifypy-test_retrieve-sometimes-fails - Exploit, Third Party Advisory | |
References | () https://groups.google.com/forum/#%21topic/s3ql/4TzCVIMkA4o - |
07 Nov 2023, 02:52
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2018-06-10 23:29
Updated : 2024-11-21 03:44
NVD link : CVE-2018-12088
Mitre link : CVE-2018-12088
CVE.ORG link : CVE-2018-12088
JSON object : View
Products Affected
s3ql_project
- s3ql
CWE
CWE-20
Improper Input Validation