First published: Tue Jun 25 2019(Updated: )
It was discovered that Ceph incorrectly handled read only permissions. An authenticated attacker could use this issue to obtain dm-crypt encryption keys. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-14662) It was discovered that Ceph incorrectly handled certain OMAPs holding bucket indices. An authenticated attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-16846) It was discovered that Ceph incorrectly sanitized certain debug logs. A local attacker could possibly use this issue to obtain encryption key information. This issue was only addressed in Ubuntu 18.10 and Ubuntu 19.04. (CVE-2018-16889) It was discovered that Ceph incorrectly handled certain civetweb requests. A remote attacker could possibly use this issue to consume resources, leading to a denial of service. This issue only affected Ubuntu 18.10 and Ubuntu 19.04. (CVE-2019-3821)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/ceph | <13.2.4+dfsg1-0ubuntu2.1 | 13.2.4+dfsg1-0ubuntu2.1 |
=19.04 | ||
All of | ||
ubuntu/ceph-common | <13.2.4+dfsg1-0ubuntu2.1 | 13.2.4+dfsg1-0ubuntu2.1 |
=19.04 | ||
All of | ||
ubuntu/ceph | <13.2.4+dfsg1-0ubuntu0.18.10.2 | 13.2.4+dfsg1-0ubuntu0.18.10.2 |
=18.10 | ||
All of | ||
ubuntu/ceph-common | <13.2.4+dfsg1-0ubuntu0.18.10.2 | 13.2.4+dfsg1-0ubuntu0.18.10.2 |
=18.10 | ||
All of | ||
ubuntu/ceph | <10.2.11-0ubuntu0.16.04.2 | 10.2.11-0ubuntu0.16.04.2 |
=16.04 | ||
All of | ||
ubuntu/ceph-common | <10.2.11-0ubuntu0.16.04.2 | 10.2.11-0ubuntu0.16.04.2 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for this advisory is USN-4035-1.
The severity of USN-4035-1 is not specified in the provided information.
USN-4035-1 affects versions 13.2.4+dfsg1-0ubuntu2.1, 13.2.4+dfsg1-0ubuntu0.18.10.2, and 10.2.11-0ubuntu0.16.04.2 of the 'ceph' and 'ceph-common' packages on various Ubuntu releases.
To fix the vulnerability, update the 'ceph' and 'ceph-common' packages to the specified remedial versions indicated in the vulnerability advisory.
You can find more information about USN-4035-1 at the following references: [USN-4035-1](https://ubuntu.com/security/CVE-2018-14662), [CVE-2018-16846](https://ubuntu.com/security/CVE-2018-16846), [CVE-2018-16889](https://ubuntu.com/security/CVE-2018-16889).