CVE-2018-1000538

Source
https://cve.org/CVERecord?id=CVE-2018-1000538
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000538.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-1000538
Downstream
Related
Published
2018-06-26T16:29:02.133Z
Modified
2025-11-20T10:45:22.923636Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Minio Inc. Minio S3 server version prior to RELEASE.2018-05-16T23-35-33Z contains a Allocation of Memory Without Limits or Throttling (similar to CWE-774) vulnerability in write-to-RAM that can result in Denial of Service. This attack appear to be exploitable via Sending V4-(pre)signed requests with large bodies . This vulnerability appears to have been fixed in after commit 9c8b7306f55f2c8c0a5c7cea9a8db9d34be8faa7.

References

Affected packages

Git / github.com/minio/minio

Affected ranges

Type
GIT
Repo
https://github.com/minio/minio
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

OFFICIAL.*

OFFICIAL.2016-02-08T00-12-28Z

RELEASE.*

RELEASE.2016-03-11T03-45-50Z
RELEASE.2016-03-21T21-08-51Z
RELEASE.2016-04-14T18-38-10Z
RELEASE.2016-06-03T19-32-05Z
RELEASE.2016-07-13T21-46-05Z
RELEASE.2016-08-16T23-19-45Z
RELEASE.2016-08-21T02-44-47Z
RELEASE.2016-09-11T17-42-18Z
RELEASE.2016-12-12T18-35-43Z
RELEASE.2016-12-12T23-44-33Z
RELEASE.2016-12-13T17-19-42Z
RELEASE.2017-08-05T00-00-53Z
RELEASE.2017-09-29T19-16-56Z
RELEASE.2017-10-27T18-59-02Z
RELEASE.2017-11-22T19-55-46Z
RELEASE.2017-12-28T01-21-00Z
RELEASE.2018-01-02T23-07-00Z
RELEASE.2018-01-18T20-33-21Z
RELEASE.2018-02-09T22-40-05Z
RELEASE.2018-03-12T21-25-28Z
RELEASE.2018-03-16T22-52-12Z
RELEASE.2018-03-19T19-22-06Z
RELEASE.2018-03-28T23-45-53Z
RELEASE.2018-03-30T00-38-44Z
RELEASE.2018-04-04T05-20-54Z
RELEASE.2018-04-12T23-41-09Z
RELEASE.2018-04-19T22-54-58Z
RELEASE.2018-04-27T23-33-52Z
RELEASE.2018-05-04T23-13-12Z
RELEASE.2018-05-10T00-00-42Z
RELEASE.2018-05-11T00-29-24Z
RELEASE.2018-05-16T23-35-33Z

Other

release-1434511043

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000538.json"