Information on source package ceph

Available versions

ReleaseVersion
jessie0.80.7-2+deb8u2
stretch10.2.5-7.2
stretch (security)10.2.11-2
buster10.2.5-7.2
sid12.2.8+dfsg1-5

Open issues

BugjessiestretchbustersidDescription
CVE-2018-1129vulnerable (no DSA)fixedvulnerablefixedA flaw was found in the way signature calculation was handled by cephx ...
CVE-2018-1128vulnerable (no DSA)fixedvulnerablefixedIt was found that cephx authentication protocol did not verify ceph ...
CVE-2018-10861vulnerable (no DSA)fixedvulnerablefixedA flaw was found in the way ceph mon handles user requests. Any ...
CVE-2017-7519fixedfixedvulnerablefixedIn Ceph, a format string flaw was found in the way libradosstriper ...

Resolved issues

BugDescription
CVE-2018-7262In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc ...
CVE-2017-16818RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote ...
CVE-2016-9579A flaw was found in the way Ceph Object Gateway would process ...
CVE-2016-8626A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object ...
CVE-2016-7031The RGW code in Ceph before 10.0.1, when authenticated-read ACL is ...
CVE-2016-5009The handle_command function in mon/Monitor.cc in Ceph allows remote ...
CVE-2015-5245CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw ...

Security announcements

DSA / DLADescription
DSA-4339-2ceph - regression update
DSA-4339-1ceph - security update

Search for package or bug name: Reporting problems