| Errata ID | 333 |
|---|---|
| Date | 2018-11-28 |
| Source package | ceph |
| Fixed in version | 10.2.11-2 |
| Description | This update addresses the following issues: * libradosstriper processes arbitrary printf placeholders in user input (CVE-2017-7519) * cephx protocol is vulnerable to replay attack (CVE-2018-1128) * cephx uses weak signatures (CVE-2018-1129) * ceph-mon does not perform authorization on OSD pool ops (CVE-2018-10861) * Fix build on i386 |
| Additional notes | |
| CVE ID | CVE-2017-7519 CVE-2018-1128 CVE-2018-1129 CVE-2018-10861 |
| UCS Bug number | #48179 |
