Lucene search

K
ubuntuUbuntuUSN-3452-1
HistoryOct 11, 2017 - 12:00 a.m.

Ceph vulnerabilities

2017-10-1100:00:00
ubuntu.com
42

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

6.9 Medium

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.3%

Releases

  • Ubuntu 14.04 ESM

Packages

  • ceph - distributed storage and file system

Details

It was discovered that Ceph incorrectly handled the handle_command
function. A remote authenticated user could use this issue to cause Ceph to
crash, resulting in a denial of service. (CVE-2016-5009)

Rahul Aggarwal discovered that Ceph incorrectly handled the
authenticated-read ACL. A remote attacker could possibly use this issue to
list bucket contents via a URL. (CVE-2016-7031)

Diluga Salome discovered that Ceph incorrectly handled certain POST objects
with null conditions. A remote attacker could possibly use this issue to
cuase Ceph to crash, resulting in a denial of service. (CVE-2016-8626)

Yang Liu discovered that Ceph incorrectly handled invalid HTTP Origin
headers. A remote attacker could possibly use this issue to cuase Ceph to
crash, resulting in a denial of service. (CVE-2016-9579)

OSVersionArchitecturePackageVersionFilename
Ubuntu14.04noarchceph< 0.80.11-0ubuntu1.14.04.3UNKNOWN
Ubuntu14.04noarchceph-common< 0.80.11-0ubuntu1.14.04.3UNKNOWN
Ubuntu14.04noarchceph-common-dbg< 0.80.11-0ubuntu1.14.04.3UNKNOWN
Ubuntu14.04noarchceph-common-dbgsym< 0.80.11-0ubuntu1.14.04.3UNKNOWN
Ubuntu14.04noarchceph-dbg< 0.80.11-0ubuntu1.14.04.3UNKNOWN
Ubuntu14.04noarchceph-dbgsym< 0.80.11-0ubuntu1.14.04.3UNKNOWN
Ubuntu14.04noarchceph-fs-common< 0.80.11-0ubuntu1.14.04.3UNKNOWN
Ubuntu14.04noarchceph-fs-common-dbg< 0.80.11-0ubuntu1.14.04.3UNKNOWN
Ubuntu14.04noarchceph-fs-common-dbgsym< 0.80.11-0ubuntu1.14.04.3UNKNOWN
Ubuntu14.04noarchceph-fuse< 0.80.11-0ubuntu1.14.04.3UNKNOWN
Rows per page:
1-10 of 441

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

6.9 Medium

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.3%