Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3979

Опубликовано: 25 авг. 2022
Источник: debian
EPSS Низкий

Описание

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cephfixed16.2.9+ds-1package
cephno-dsabullseyepackage
cephno-dsastretchpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2022/01/11/5

  • https://tracker.ceph.com/issues/54006

  • https://github.com/ceph/ceph/commit/47c33179f9a15ae95cc1579a421be89378602656 (main)

  • https://github.com/ceph/ceph/commit/f69339e00f582ec64b843ff58b66817975fca0d7 (v16.2.8)

EPSS

Процентиль: 42%
0.00199
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

CVSS3: 6.5
redhat
больше 3 лет назад

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

CVSS3: 6.5
nvd
почти 3 года назад

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

suse-cvrf
больше 2 лет назад

Security update for ceph

suse-cvrf
почти 3 года назад

Security update for ceph

EPSS

Процентиль: 42%
0.00199
Низкий