Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for ceph to version ceph-12.2.5-419-g8cbf63d997 fixes the following issues: - CVE-2018-10861: Ensure that ceph-mon does perform authorization on all OSD pool ops (bsc#1099162). - CVE-2018-1129: cephx signature check bypass (bsc#1096748). - CVE-2018-1128: cephx protocol was vulnerable to replay attack (bsc#1096748). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2018-1296=1 Package List: - SUSE Enterprise Storage 5 (aarch64 x86_64): ceph-12.2.5+git.1530082629.8cbf63d997-2.16.1 ceph-base-12.2.5+git.1530082629.8cbf63d997-2.16.1
#1096748 #1099162
Cross- CVE-2018-10861 CVE-2018-1128 CVE-2018-1129
Affected Products:
SUSE Enterprise Storage 5
https://www.suse.com/security/cve/CVE-2018-10861.html
https://www.suse.com/security/cve/CVE-2018-1128.html
https://www.suse.com/security/cve/CVE-2018-1129.html
https://bugzilla.suse.com/1096748
https://bugzilla.suse.com/1099162
Get the latest Linux and open source security news straight to your inbox.