CVE-2019-3821: High severity ceph civetweb vulnerability
A flaw was found in rados gateway shipped as part of ceph. Unclosed file descriptors while denying TCP connections to SSL serving port pile up until exhaustion of resources leading to potencial remote denial of service.
Other sources
A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors for ceph-radosgw service resulting in a remote denial of service.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-3821?
CVE-2019-3821 is a vulnerability found in the way civetweb frontend handles requests for ceph RGW server with SSL enabled, allowing an unauthenticated attacker to create multiple connections and exhaust file descriptors, leading to a remote denial of service.
Which software is affected by CVE-2019-3821?
The software affected by CVE-2019-3821 includes Ceph Civetweb, Canonical Ubuntu Linux 16.04 LTS, Canonical Ubuntu Linux 18.10, and Canonical Ubuntu Linux 19.04.
What is the severity of CVE-2019-3821?
CVE-2019-3821 has a severity rating of 7.5 (High).
How can I fix CVE-2019-3821 on Ubuntu?
To fix CVE-2019-3821 on Ubuntu, you can update the ceph package to version 13.2.4+dfsg1-0ubuntu0.18.10.2 for Ubuntu 18.10 (Cosmic) or version 13.2.4+dfsg1-0ubuntu2.1 for Ubuntu 19.04 (Disco).
Are there any references for CVE-2019-3821?
Yes, you can find references for CVE-2019-3821 at the following links: [Bugzilla Red Hat](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3821), [GitHub](https://github.com/ceph/civetweb/pull/33), [Ubuntu Security Notice](https://usn.ubuntu.com/4035-1/).