SUSE-SU-2018:1576-1
Dashboard / Vulnerabilities / SUSE-SU-2018:1576-1
SUSE-SU-2018:1576-1
Summary: Security update for ceph
Details: This update for ceph to 12.2.5-407-g5e7ea8cf03 fixes the following issues: Security issue fixed: - CVE-2018-7262: The rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service. rgw: make init env methods return an error (bsc#1081379) Other issues fixed: - osd: do not crash on empty snapset (bsc#1074301) - mon: add 'ceph osd pool get erasure allow_ec_overwrites' command (bsc#1087269) - journal: limit number of appends sent in one librados op (bsc#1086340) - RGW user stats fixes (bsc#1087493) - rgw openssl fixes (bsc#1079076, bsc#1081379) - rocksdb: fixes early metadata spill over to slow device in bluefs (bsc#1071386) - mon: reenable timer to send digest when paxos is temporarily inactive (bsc#1070357) - fsid mismatch when creating additional OSDs (bsc#1080788) - crash in civetweb/RGW (bsc#1081600)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20181576-1/, https://bugzilla.suse.com/1070357, https://bugzilla.suse.com/1071386, https://bugzilla.suse.com/1074301, https://bugzilla.suse.com/1079076, https://bugzilla.suse.com/1080788, https://bugzilla.suse.com/1081379, https://bugzilla.suse.com/1081600, https://bugzilla.suse.com/1086340, https://bugzilla.suse.com/1087269, https://bugzilla.suse.com/1087493, https://www.suse.com/security/cve/CVE-2018-7262
Affected packages
Package
Name: ceph
Purl: pkg:rpm/suse/ceph&distro=SUSE%20Enterprise%20Storage%205
Affected ranges
Type: ECOSYSTEM
Events:
