Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Warning: Undefined array key "Description" in /var/www/www.linuxsecurity.com-443/html/lsadvisories/lsadvisories.php on line 220

Fedora 31: FEDORA-2020-81b9c6cddc High: Ceph XSS and Integrity Issues

fedora
Calendar Grey May 7, 2020
Dist Fedora Esm H88
Ceph 14.2.9 security patch resolves privacy and cross-site scripting vulnerabilities. Upgrade immediately to protect your Fedora 31 environment.
ceph-14.2.9 GA Security fix for CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS Security fix for CVE-2020-1759 ceph: secure mode of msgr2 breaks both confi...

Summary

Ceph is a massively scalable, open-source, distributed storage system that runs

on commodity hardware and delivers object, block and file system storage.

ceph-14.2.9 GA Security fix for CVE-2020-1760 ceph: header-splitting in RGW

GetObject has a possible XSS Security fix for CVE-2020-1759 ceph: secure mode of

msgr2 breaks both confidentiality and integrity aspects for long-lived sessions

* Tue Apr 21 2020 Kaleb S. KEITHLEY - 2:14.2.9-1

- ceph 14.2.9 GA, resync w/ upstream ceph.spec(.in)

[ 1 ] Bug #1821586 - CVE-2020-1759 ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1821586

[ 2 ] Bug #1821587 - CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1821587

su -c 'dnf upgrade --advisory FEDORA-2020-81b9c6cddc' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 31
Version: 14.2.9
Release: 1.fc31
URL: Summary : User space components of the Ceph file system

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here