Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-7262

Опубликовано: 13 фев. 2018
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service.

A NULL pointer dereference flaw was found in RADOS Gateway HTTP request handling when using the Civetweb native webserver. An unauthenticated attacker could crash RADOS Gateway server by sending malicious HTTP requests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.3cephNot affected
Red Hat Ceph Storage 2cephNot affected
Red Hat Enterprise Linux 7ceph-commonNot affected
Red Hat Enterprise Linux 8cephNot affected
Red Hat Ceph Storage 3.0cephFixedRHSA-2018:054615.03.2018
Red Hat Ceph Storage 3 for UbuntuFixedRHSA-2018:054815.03.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1546610ceph: Unauthenticated malformed HTTP requests handled by rgw_civetweb.cc:RGW::init_env() can lead to denial of service

EPSS

Процентиль: 86%
0.02924
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service.

CVSS3: 7.5
nvd
больше 8 лет назад

In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service.

CVSS3: 7.5
debian
больше 8 лет назад

In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGW ...

CVSS3: 7.5
github
больше 4 лет назад

In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service.

suse-cvrf
около 8 лет назад

Security update for ceph

EPSS

Процентиль: 86%
0.02924
Низкий

7.3 High

CVSS3