First published: Mon Feb 19 2018(Updated: )
In ceph, HTTP request headers without a ":" character that are handled in rgw_civetweb.cc:RGW::init_env() can cause variables to be set to NULL, leading to a crash or other potentially unspecified behaviour. Upstream Pull Request: <a href="https://github.com/ceph/ceph/pull/20403">https://github.com/ceph/ceph/pull/20403</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Ceph |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1546610 is considered critical due to the potential for application crashes and unspecified behavior.
To fix REDHAT-BUG-1546610, update to the latest version of Ceph where the issue has been addressed.
REDHAT-BUG-1546610 affects multiple versions of Ceph, and the specific affected versions should be checked in the release notes.
The potential impacts of REDHAT-BUG-1546610 include application crashes and instability, leading to a lack of service availability.
Currently, there are no known workarounds for REDHAT-BUG-1546610 aside from applying the recommended updates.