It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/101554 | third party advisory vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15085 | vendor advisory issue tracking |
https://access.redhat.com/errata/RHSA-2017:3110 | vendor advisory |