The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ceph | Jul 30, 2024 | Jul 12, 2016 |
| Redhat_linux | — | Upgrade ceph-debuginfoUpgrade ceph-commonUpgrade ceph-radosgwUpgrade python-radosUpgrade python-rbdUpgrade ceph-selinux | Jul 30, 2016 | Jul 5, 2016 |
| Suse | — | Upgrade ceph-commonUpgrade libradosstriper1Upgrade librbd1Upgrade libcephfs1Upgrade python-rbdUpgrade librbd-develUpgrade librados-develUpgrade librados2Upgrade libcephfs-develUpgrade python-cephfsUpgrade libradosstriper-develUpgrade python-rados | Dec 19, 2016 | Jul 12, 2016 |
| Ubuntu | — | Upgrade cephUpgrade ceph-common | Oct 11, 2017 | Jul 12, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub