#VU13068 Assertion failure in Ceph - CVE-2017-16818
Published: May 30, 2018 / Updated: May 31, 2018
Ceph
Red Hat Inc.
Description
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.
The vulnerability exists due to assertion failure and application exit. A remote attacker can leverage "full" privileges, post an invalid profile to the admin API, related to rgw/rgw_iam_policy.cc, rgw/rgw_basic_types.h, and rgw/rgw_iam_types.h and cause the service to crash.