** Description changed:

- [libceph: missing validation of the auth reply]
+ net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3,
+ does not properly validate auth replies, which allows remote attackers
+ to cause a denial of service (system crash) or possibly have unspecified
+ other impact via crafted data from the IP address of a Ceph Monitor.
  
  Break-Fix: ec0994e48ea2aebf62ff08376227f3a9ccf46262
  c27a3e4d667fdcad3db7b104f75659478e0c68d8

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1370047

Title:
  CVE-2014-6418

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1370047/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to