CVE-2018-10861

NameCVE-2018-10861
DescriptionA flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-4339-1
NVD severitymedium (attack range: remote)
Debian Bugs913470

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ceph (PTS)jessie0.80.7-2+deb8u2vulnerable
jessie (security)0.80.7-2+deb8u3vulnerable
stretch (security), stretch10.2.11-2fixed
buster, bullseye, sid12.2.11+dfsg1-2.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cephsource(unstable)12.2.8+dfsg1-1medium913470
cephsourcestretch10.2.11-1mediumDSA-4339-1

Notes

[jessie] - ceph <no-dsa> (Intrusive changes)
http://tracker.ceph.com/issues/24838
https://github.com/ceph/ceph/commit/975528f632f73fbffa3f1fee304e3bbe3296cffc

Search for package or bug name: Reporting problems