Wind River Support Network

HomeDefectsLIN1018-3807
Fixed

LIN1018-3807 : Security Advisory - ceph - CVE-2019-3821

Created: Mar 28, 2019    Updated: Apr 28, 2019
Resolved Date: Apr 22, 2019
Found In Version: unknown
Fix Version: 10.18.44.6
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors for ceph-radosgw service resulting in a remote denial of service.

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2019-3821 User=admin}

CVEs


Live chat
Online