Bug#891963: closed by Gaudenz Steinlin (Re: [Ceph-maintainers] Bug#891963: ceph: CVE-2018-7262)

2018-03-17 Thread Salvatore Bonaccorso
Hi Gaudenz, > Gaudenz Steinlin writes: > > > Hi > > > > Salvatore Bonaccorso writes: > >> Hi, > >> > >> the following vulnerability was published for ceph. > >> > >> CVE-2018-7262[0]: > >> |Malformed HTTP requests handled in rgw_civetweb.cc:RGW::init_env() can > >> |lead to NULL pointer derefe

Bug#891963: [Ceph-maintainers] Bug#891963: ceph: CVE-2018-7262

2018-03-06 Thread Gaudenz Steinlin
Hi Salvatore Bonaccorso writes: > Hi, > > the following vulnerability was published for ceph. > > CVE-2018-7262[0]: > |Malformed HTTP requests handled in rgw_civetweb.cc:RGW::init_env() can > |lead to NULL pointer dereference Thanks for the information. I backported the upstream fix to the ver

Bug#891963: ceph: CVE-2018-7262

2018-03-03 Thread Salvatore Bonaccorso
Source: ceph Version: 10.2.5-1 Severity: important Tags: security upstream Forwarded: http://tracker.ceph.com/issues/23039 Hi, the following vulnerability was published for ceph. CVE-2018-7262[0]: |Malformed HTTP requests handled in rgw_civetweb.cc:RGW::init_env() can |lead to NULL pointer deref