SUSE-SU-2016:0806-1
Dashboard / Vulnerabilities / SUSE-SU-2016:0806-1
SUSE-SU-2016:0806-1
Summary: Security update for ceph
Details: This update provides Ceph 0.8.11, which fixes the following security issue: - CVE-2015-5245: A CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) could allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name. (bsc#945206) The following non-security issues have been fixed: - Move ceph-rbdnamer binary from package 'ceph' to 'ceph-common'. (bsc#965619) - Install /usr/bin/radosgw with mode 0750 and owner root:www. (bsc#964907) - Loop over all ceph-related systemd units on rpm removal. (bsc#941628) - Perform ceph-disk activate in separate systemd services, rather than in udev directly. (bsc#926756) - Add hyphen to systemctl reload in logrotate.conf to avoid matching ceph.target. (bsc#931451) Ceph 0.8.11 also brings a significant number of bug fixes and enhancements. For a comprehensive list please refer to the package's change log.
References: https://www.suse.com/support/update/announcement/2016/suse-su-20160806-1/, https://bugzilla.suse.com/926756, https://bugzilla.suse.com/931451, https://bugzilla.suse.com/941628, https://bugzilla.suse.com/945206, https://bugzilla.suse.com/964907, https://bugzilla.suse.com/965619, https://www.suse.com/security/cve/CVE-2015-5245
Affected packages
Package
Name: ceph
Purl: pkg:rpm/suse/ceph&distro=SUSE%20Enterprise%20Storage%201.0
Affected ranges
Type: ECOSYSTEM
Events:
