Denial of service in Ceph - CVE-2018-7262
Published: March 22, 2018
Vulnerability identifier: #VU11220
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7262
CWE-ID: CWE-113
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to perform HTTP response splitting attack.
The weakness exists in the rgw_civetweb.cc RGWCivetWeb::init_envfunction due to improper handling of HTTP headers. A remote attacker can send a specially crafted HTTP header and cause the service to crash.
The weakness exists in the rgw_civetweb.cc RGWCivetWeb::init_envfunction due to improper handling of HTTP headers. A remote attacker can send a specially crafted HTTP header and cause the service to crash.
Affected software
Ceph
Red Hat Ceph Storage
Fedora
Opensuse
openSUSE Leap
ceph
Red Hat Ceph Storage
Fedora
Opensuse
openSUSE Leap
ceph
How to mitigate CVE-2018-7262
Update to version 12.2.3.
Red Hat Ceph Storage - update to 3
ceph - update to 12.2.4-1.fc27
ceph - update to 12.2.4-1.fc27