USN-3452-1
Dashboard / Vulnerabilities / USN-3452-1
USN-3452-1
Summary: ceph vulnerabilities
Details: It was discovered that Ceph incorrectly handled the handle_command function. A remote authenticated user could use this issue to cause Ceph to crash, resulting in a denial of service. (CVE-2016-5009) Rahul Aggarwal discovered that Ceph incorrectly handled the authenticated-read ACL. A remote attacker could possibly use this issue to list bucket contents via a URL. (CVE-2016-7031) Diluga Salome discovered that Ceph incorrectly handled certain POST objects with null conditions. A remote attacker could possibly use this issue to cuase Ceph to crash, resulting in a denial of service. (CVE-2016-8626) Yang Liu discovered that Ceph incorrectly handled invalid HTTP Origin headers. A remote attacker could possibly use this issue to cuase Ceph to crash, resulting in a denial of service. (CVE-2016-9579)
References: https://ubuntu.com/security/notices/USN-3452-1, https://ubuntu.com/security/CVE-2016-5009, https://ubuntu.com/security/CVE-2016-7031, https://ubuntu.com/security/CVE-2016-8626, https://ubuntu.com/security/CVE-2016-9579
Affected packages
Package
Name: ceph
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
