CVE-2018-12088

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
10/06/2018
Last modified:
07/11/2023

Description

S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files, or temporarily hide parts of files. This is related to the checksum_basic_mapping function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:s3ql_project:s3ql:*:*:*:*:*:*:*:* 2.27 (excluding)