CVE-2018-12088
S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files, or temporarily hide parts of files. This is related to the checksum_basic_mapping function.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.88% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- s3ql project/s3ql
- Source
- cve@mitre.org
References
- https://bitbucket.org/nikratio/s3ql/commits/85aba5c2d5c81453a73a50ed638adaeef0521020Patch, Third Party Advisory
- https://bitbucket.org/nikratio/s3ql/issues/272/t3_verifypy-test_retrieve-sometimes-failsExploit, Third Party Advisory
- https://groups.google.com/forum/#%21topic/s3ql/4TzCVIMkA4o
- https://bitbucket.org/nikratio/s3ql/commits/85aba5c2d5c81453a73a50ed638adaeef0521020Patch, Third Party Advisory
- https://bitbucket.org/nikratio/s3ql/issues/272/t3_verifypy-test_retrieve-sometimes-failsExploit, Third Party Advisory
- https://groups.google.com/forum/#%21topic/s3ql/4TzCVIMkA4o
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.