The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 02:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-updates/2016-12/msg00126.html - | |
References | () http://tracker.ceph.com/issues/16297 - Vendor Advisory | |
References | () https://access.redhat.com/errata/RHSA-2016:1384 - | |
References | () https://access.redhat.com/errata/RHSA-2016:1385 - | |
References | () https://github.com/ceph/ceph/commit/957ece7e95d8f8746191fd9629622d4457d690d6 - | |
References | () https://github.com/ceph/ceph/pull/9700 - |
Information
Published : 2016-07-12 19:59
Updated : 2024-11-21 02:53
NVD link : CVE-2016-5009
Mitre link : CVE-2016-5009
CVE.ORG link : CVE-2016-5009
JSON object : View
Products Affected
redhat
- enterprise_linux_for_scientific_computing
- enterprise_linux_server
- enterprise_linux_desktop
- ceph_storage_mon
- ceph_storage_osd
- ceph
- enterprise_linux_workstation
CWE
CWE-20
Improper Input Validation