Описание
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
A flaw was found in the way handle_command() function would validate prefix value from user. An authenticated attacker could send a specially crafted prefix value resulting in ceph monitor crash.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | ceph | Not affected | ||
| Red Hat Enterprise Linux 7 | ceph-common | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | ceph | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | ceph | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | ceph | Not affected | ||
| Red Hat Ceph Storage 1.3 for Red Hat Enterprise Linux 7 | ceph | Fixed | RHSA-2016:1384 | 05.07.2016 |
| Red Hat Ceph Storage 1.3 for Ubuntu | Fixed | RHSA-2016:1385 | 05.07.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.9 Medium
CVSS3
4.9 Medium
CVSS2
Связанные уязвимости
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
The handle_command function in mon/Monitor.cc in Ceph allows remote au ...
EPSS
4.9 Medium
CVSS3
4.9 Medium
CVSS2