Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1129

Опубликовано: 10 июл. 2018
Источник: debian

Описание

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.19.9-1package
linuxfixed4.9.144-1stretchpackage
linuxnot-affectedjessiepackage
cephfixed12.2.8+dfsg1-1package
cephno-dsajessiepackage

Примечания

  • https://git.kernel.org/linus/cc255c76c70f7a87d97939621eae04b600d9f4a1

  • http://tracker.ceph.com/issues/24837

  • https://github.com/ceph/ceph/commit/8f396cf35a3826044b089141667a196454c0a587

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 8 лет назад

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

CVSS3: 5.9
redhat
около 8 лет назад

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

CVSS3: 6.5
nvd
около 8 лет назад

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

CVSS3: 6.5
msrc
6 месяцев назад

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master mimic luminous and jewel are believed to be vulnerable.

CVSS3: 6.5
github
больше 4 лет назад

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.