The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ceph | Jul 30, 2024 | Jul 12, 2016 |
| Redhat_linux | — | Upgrade ceph-radosgwUpgrade ceph-commonUpgrade ceph-debuginfoUpgrade python-rbdUpgrade python-radosUpgrade ceph-selinux | Jul 30, 2016 | Jul 5, 2016 |
| Suse | — | Upgrade python-rbdUpgrade libcephfs1Upgrade librbd1Upgrade libradosstriper1Upgrade ceph-commonUpgrade libradosstriper-develUpgrade librbd-develUpgrade librados2Upgrade librados-develUpgrade python-radosUpgrade libcephfs-develUpgrade python-cephfs | Dec 19, 2016 | Jul 12, 2016 |
| Ubuntu | — | Upgrade ceph-commonUpgrade ceph | Oct 11, 2017 | Jul 12, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub