Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for ceph to 12.2.5-407-g5e7ea8cf03 fixes the following issues: Security issue fixed: - CVE-2018-7262: The rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service. rgw: make init env methods return an error (bsc#1081379) Other issues fixed: - osd: do not crash on empty snapset (bsc#1074301) - mon: add 'ceph osd pool get erasure allow_ec_overwrites' command (bsc#1087269) - journal: limit number of appends sent in one librados op (bsc#1086340) - RGW user stats fixes (bsc#1087493) - rgw openssl fixes (bsc#1079076, bsc#1081379) - rocksdb: fixes early metadata spill over to slow device in bluefs (bsc#1071386) - mon: reenable timer to send digest when paxos is temporarily inactive (bsc#1070357)
#1070357 #1071386 #1074301 #1079076 #1080788
#1081379 #1081600 #1086340 #1087269 #1087493
Cross- CVE-2018-7262
Affected Products:
SUSE Enterprise Storage 5
https://www.suse.com/security/cve/CVE-2018-7262.html
https://bugzilla.suse.com/1070357
https://bugzilla.suse.com/1071386
https://bugzilla.suse.com/1074301
https://bugzilla.suse.com/1079076
https://bugzilla.suse.com/1080788
https://bugzilla.suse.com/1081379
https://bugzilla.suse.com/1081600
https://bugzilla.suse.com/1086340
https://bugzilla.suse.com/1087269
https://bugzilla.suse.com/1087493
Get the latest Linux and open source security news straight to your inbox.