Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1546610 - (CVE-2018-7262) CVE-2018-7262 ceph: Unauthenticated malformed HTTP requests handled by rgw_civetweb.cc:RGW::init_env() can lead to denial of service
CVE-2018-7262 ceph: Unauthenticated malformed HTTP requests handled by rgw_ci...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20180213,repo...
: Reopened, Security
Depends On: 1546611 1546613 1547673 1548926 1548927 1548928
Blocks: 1546612 1550199
  Show dependency treegraph
 
Reported: 2018-02-18 21:57 EST by Sam Fowler
Modified: 2018-05-23 05:35 EDT (History)
13 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A NULL pointer dereference flaw was found in RADOS Gateway HTTP request handling when using the Civetweb native webserver. An unauthenticated attacker could crash RADOS Gateway server by sending malicious HTTP requests.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-05-23 05:35:44 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:0546 None None None 2018-03-15 14:29 EDT
Red Hat Product Errata RHSA-2018:0548 None None None 2018-03-15 14:31 EDT

  None (edit)
Description Sam Fowler 2018-02-18 21:57:00 EST
In ceph, HTTP request headers without a ":" character that are handled in rgw_civetweb.cc:RGW::init_env() can cause variables to be set to NULL, leading to a crash or other potentially unspecified behaviour.

Upstream Pull Request:

https://github.com/ceph/ceph/pull/20403
Comment 1 Sam Fowler 2018-02-18 21:57:35 EST
Created ceph tracking bugs for this issue:

Affects: fedora-all [bug 1546611]
Comment 7 Siddharth Sharma 2018-02-25 22:58:32 EST
Upstream Pull Request:

https://github.com/ceph/ceph/pull/20564
Comment 12 errata-xmlrpc 2018-03-15 14:29:20 EDT
This issue has been addressed in the following products:

  Red Hat Ceph Storage 3.0 for Ubuntu 16.04

Via RHSA-2018:0546 https://access.redhat.com/errata/RHSA-2018:0546
Comment 13 errata-xmlrpc 2018-03-15 14:30:55 EDT
This issue has been addressed in the following products:

  Red Hat Ceph Storage 3 for Red Hat Enterprise Linux 7

Via RHSA-2018:0548 https://access.redhat.com/errata/RHSA-2018:0548
Comment 16 Boris Ranto 2018-05-22 18:39:07 EDT
This was fixed upstream in 12.2.4, the latest rebase fixed it downstream, too.
Comment 17 Boris Ranto 2018-05-22 18:42:40 EDT
I am sorry, I had too many tabs opened and I have accidentally closed the wrong bug.

Note You need to log in before you can comment on or make changes to this bug.