CVE-2016-8626: Input Validation
A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launch a denial of service attack by sending null or specially crafted POST object requests.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8626?
The severity of CVE-2016-8626 is medium.
How does CVE-2016-8626 affect Red Hat Ceph?
CVE-2016-8626 affects Red Hat Ceph versions before 0.94.9-8.
Can an authenticated attacker launch a denial of service attack using CVE-2016-8626?
Yes, an authenticated attacker can launch a denial of service attack by sending null or specially crafted POST object requests.
Which versions of Red Hat Enterprise Linux are affected by CVE-2016-8626?
Red Hat Enterprise Linux Desktop, Server, and Workstation versions 7.0 are affected by CVE-2016-8626.
Are there any references for CVE-2016-8626?
Yes, you can find references for CVE-2016-8626 at the following links: [http://rhn.redhat.com/errata/RHSA-2016-2815.html](http://rhn.redhat.com/errata/RHSA-2016-2815.html), [http://rhn.redhat.com/errata/RHSA-2016-2816.html](http://rhn.redhat.com/errata/RHSA-2016-2816.html), [http://rhn.redhat.com/errata/RHSA-2016-2847.html](http://rhn.redhat.com/errata/RHSA-2016-2847.html).