Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2018:1417-1 Important: Ceph DoS and Header Crashes

suse
Calendar Grey May 24, 2018
Scroller Suse
SUSE Security Update for apache critical advisory: rectifies significant vulnerabilities and enhances overall system performance and safety.
An update that solves two vulnerabilities and has 21 fixes is now available

Summary

This update for ceph fixes the following issues: Security issues fixed: - CVE-2018-7262: rgw: malformed http headers can crash rgw (bsc#1081379). - CVE-2017-16818: User reachable asserts allow for DoS (bsc#1063014). Bug fixes: - bsc#1061461: OSDs keep generating coredumps after adding new OSD node to cluster. - bsc#1079076: RGW openssl fixes. - bsc#1067088: Upgrade to SES5 restarted all nodes, majority of OSDs aborts during start. - bsc#1056125: Some OSDs are down when doing performance testing on rbd image in EC Pool. - bsc#1087269: allow_ec_overwrites option not in command options list. - bsc#1051598: Fix mountpoint check for systemctl enable --runtime. - bsc#1070357: Zabbix mgr module doesn't recover from HEALTH_ERR. - bsc#1066502: After upgrading a single OSD from SES 4 to SES 5 the OSDs

References

#1051598 #1054061 #1056125 #1056967 #1059458

#1060904 #1061461 #1063014 #1066182 #1066502

#1067088 #1067119 #1067705 #1070357 #1071386

#1074301 #1079076 #1080788 #1081379 #1081600

#1086340 #1087269 #1087493

Cross- CVE-2017-16818 CVE-2018-7262

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Desktop 12-SP3

SUSE CaaS Platform ALL

https://www.suse.com/security/cve/CVE-2017-16818.html

https://www.suse.com/security/cve/CVE-2018-7262.html

https://bugzilla.suse.com/1051598

https://bugzilla.suse.com/1054061

https://bugzilla.suse.com/1056125

https://bugzilla.suse.com/1056967

https://bugzilla.suse.com/1059458

https://bugzilla.suse.com/1060904

https://bugzilla.suse.com/1061461

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:1417-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.