{"id":"UBUNTU-CVE-2018-12088","details":"S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files, or temporarily hide parts of files. This is related to the checksum_basic_mapping function.","modified":"2025-10-24T04:47:03Z","published":"2018-06-10T23:29:00Z","upstream":["CVE-2018-12088"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-12088"},{"type":"REPORT","url":"https://groups.google.com/forum/#!topic/s3ql/4TzCVIMkA4o"},{"type":"REPORT","url":"https://bitbucket.org/nikratio/s3ql/commits/85aba5c2d5c81453a73a50ed638adaeef0521020"},{"type":"REPORT","url":"https://bitbucket.org/nikratio/s3ql/issues/272/t3_verifypy-test_retrieve-sometimes-fails"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2018-12088"}],"affected":[{"package":{"name":"s3ql","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/s3ql@2.15+dfsg-1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.13+dfsg-2","2.15+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"s3ql","binary_version":"2.15+dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-12088.json"}},{"package":{"name":"s3ql","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/s3ql@2.26+dfsg-4?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.23+dfsg-1","2.24+dfsg-1","2.25+dfsg-1","2.26+dfsg-1ubuntu1","2.26+dfsg-1ubuntu2","2.26+dfsg-3ubuntu1","2.26+dfsg-4"],"ecosystem_specific":{"binaries":[{"binary_version":"2.26+dfsg-4","binary_name":"s3ql"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-12088.json"}},{"package":{"name":"s3ql","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/s3ql@3.3.2+dfsg-1ubuntu1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2+dfsg-3","3.3.2+dfsg-1","3.3.2+dfsg-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"3.3.2+dfsg-1ubuntu1","binary_name":"s3ql"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-12088.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"Ubuntu","score":"low"}]}