-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: ceph security update
Advisory ID:       RHSA-2019:2579-01
Product:           Red Hat Ceph Storage
Advisory URL:      https://access.redhat.com/errata/RHSA-2019:2579
Issue date:        2019-08-28
CVE Names:         CVE-2019-10222 
====================================================================
1. Summary:

An update is now available for Red Hat Ceph Storage 3.3 on Ubuntu 16.04.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Red Hat Ceph Storage is a scalable, open, software-defined storage platform
that combines the most stable version of the Ceph storage system with a
Ceph management platform, deployment utilities, and support services.

Security Fix(es):

* ceph: Unauthenticated clients can crash ceph RGW configured with beast as
frontend (CVE-2019-10222)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

ingle/installation_guide_for_ubuntu/index#upgrading-the-storage-cluster

4. Bugs fixed (https://bugzilla.redhat.com/):

1739292 - CVE-2019-10222 ceph: Unauthenticated clients can crash ceph RGW configured with beast as frontend

5. References:

https://access.redhat.com/security/cve/CVE-2019-10222
https://access.redhat.com/security/updates/classification/#important

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2019 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXWbO+9zjgjWX9erEAQiUURAApvs2Vsv6Ay52D6N6ygaTNSoL1qzIKHWU
RvJmxm/WkI1nHo5SJ6mSuUApGvFD6vMDL1spsuorJBSA+dAdhyS2GrLkYQ63tJw7
UlCj5lxjHb1U2iCRU95xID693aJjA+lZvNmtcHgmVPcayh+NSaJKQtacXRVCe1nO
8795THwy4vlpEcI84FtuSWnAJHUPGYH4yVOUnmzFcz2pnvyNyAGoGqQuxcCZKC81
9w0oDsX0Sw8uA+8wh8tPa7gekiH+X2zINkQcQVk7J9obmx36QdDm8RgOX48SBISF
SMQC6mAW2n2K77Lfocng0Qvl3REt9IBQFDi5Mp4gWLVRFCz77oI/ML0U7+t8ozg7
KtdlL245D1K89ZfWFGehpI2WQz5Oz+BBTm+bk66KyJdhA6x3hiWEJWuTZnZaAq/w
gUp4yaA06lyt4oIeg3WlFURxRmqPZlMcw33zwIpVFgVRjw5NNP4nflHYqfbjzR3r
l1PHqWeRUFYt37hTWUxSZ6f4jYfPS/O+PHTDPDQ5XFU//vTCQOXcZfLhYYn3R4In
a/Xx2LlBSwsjvcMeMkWoXkIfltD30Ey0aF/l8u792vXy/ooJMBha8Gry3pXiSgcw
25Miff94JpAbwP9PfWVaLQ+seX78B8WZZbyhUKAzaWj8Z3nUHmKGxOeNT/iDTX3c
+KmDjVMmztw=6qT0
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2019-2579:01 Important: ceph security update

An update is now available for Red Hat Ceph Storage 3.3 on Ubuntu 16.04

Summary

Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system with a Ceph management platform, deployment utilities, and support services.
Security Fix(es):
* ceph: Unauthenticated clients can crash ceph RGW configured with beast as frontend (CVE-2019-10222)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
ingle/installation_guide_for_ubuntu/index#upgrading-the-storage-cluster

References

https://access.redhat.com/security/cve/CVE-2019-10222 https://access.redhat.com/security/updates/classification/#important

Package List


Severity
Advisory ID: RHSA-2019:2579-01
Product: Red Hat Ceph Storage
Advisory URL: https://access.redhat.com/errata/RHSA-2019:2579
Issued Date: : 2019-08-28
CVE Names: CVE-2019-10222

Topic

An update is now available for Red Hat Ceph Storage 3.3 on Ubuntu 16.04.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

1739292 - CVE-2019-10222 ceph: Unauthenticated clients can crash ceph RGW configured with beast as frontend


Related News