SUSE-SU-2018:2299-1
Dashboard / Vulnerabilities / SUSE-SU-2018:2299-1
SUSE-SU-2018:2299-1
Summary: Security update for ceph
Details: This update for ceph fixes the following issues: Security issues fixed: - CVE-2018-10861: Fix ceph-mon authorization on OSD pool ops (bsc#1099162). - CVE-2018-1128: Fix cephx signature check bypass (bsc#1096748). - CVE-2018-1129: Fix cephx protocol vulnerability to replay attack (bsc#1096748). - CVE-2018-7262: Fix malformed http headers that can crash rgw (bsc#1081379). Bug fixes: - bsc#1072512: multipart uploads are broken if the bucket has been resharded - bsc#1080112: rgw: user stats increased after bucket reshard - bsc#1086340: SES5: XFS metadata corruption on rbd-nbd mapped image with journaling feature enabled
References: https://www.suse.com/support/update/announcement/2018/suse-su-20182299-1/, https://bugzilla.suse.com/1072512, https://bugzilla.suse.com/1080112, https://bugzilla.suse.com/1081379, https://bugzilla.suse.com/1086340, https://bugzilla.suse.com/1096748, https://bugzilla.suse.com/1099162, https://www.suse.com/security/cve/CVE-2018-10861, https://www.suse.com/security/cve/CVE-2018-1128, https://www.suse.com/security/cve/CVE-2018-1129, https://www.suse.com/security/cve/CVE-2018-7262
Affected packages
Package
Name: ceph
Purl: pkg:rpm/suse/ceph&distro=SUSE%20Enterprise%20Storage%204
Affected ranges
Type: ECOSYSTEM
Events:
