{"affected":[{"ecosystem_specific":{"binaries":[{"ceph":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","ceph-base":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","ceph-common":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","ceph-fuse":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","ceph-mds":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","ceph-mgr":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","ceph-mon":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","ceph-osd":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","ceph-radosgw":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","libcephfs2":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","librados2":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","libradosstriper1":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","librbd1":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","librgw2":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","python-ceph-compat":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","python-cephfs":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","python-rados":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","python-rbd":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","python-rgw":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","python3-ceph-argparse":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","python3-cephfs":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","python3-rados":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","python3-rbd":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","python3-rgw":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","rbd-fuse":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","rbd-mirror":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3","rbd-nbd":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3"}]},"package":{"ecosystem":"SUSE:Enterprise Storage 5","name":"ceph","purl":"pkg:rpm/suse/ceph&distro=SUSE%20Enterprise%20Storage%205"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"12.2.5+git.1524775272.5e7ea8cf03-2.13.3"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\n  \nThis update for ceph to 12.2.5-407-g5e7ea8cf03 fixes the following issues:\n\nSecurity issue fixed:\n\n- CVE-2018-7262: The rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service. rgw: make init env methods return an error (bsc#1081379)\n\nOther issues fixed:\n\n- osd: do not crash on empty snapset (bsc#1074301)\n- mon: add 'ceph osd pool get erasure allow_ec_overwrites' command (bsc#1087269)\n- journal: limit number of appends sent in one librados op (bsc#1086340)\n- RGW user stats fixes (bsc#1087493)\n- rgw openssl fixes (bsc#1079076, bsc#1081379)\n- rocksdb: fixes early metadata spill over to slow device in bluefs (bsc#1071386)\n- mon: reenable timer to send digest when paxos is temporarily inactive (bsc#1070357)\n- fsid mismatch when creating additional OSDs (bsc#1080788)\n- crash in civetweb/RGW (bsc#1081600) \n","id":"SUSE-SU-2018:1576-1","modified":"2018-06-07T13:11:11Z","published":"2018-06-07T13:11:11Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20181576-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1070357"},{"type":"REPORT","url":"https://bugzilla.suse.com/1071386"},{"type":"REPORT","url":"https://bugzilla.suse.com/1074301"},{"type":"REPORT","url":"https://bugzilla.suse.com/1079076"},{"type":"REPORT","url":"https://bugzilla.suse.com/1080788"},{"type":"REPORT","url":"https://bugzilla.suse.com/1081379"},{"type":"REPORT","url":"https://bugzilla.suse.com/1081600"},{"type":"REPORT","url":"https://bugzilla.suse.com/1086340"},{"type":"REPORT","url":"https://bugzilla.suse.com/1087269"},{"type":"REPORT","url":"https://bugzilla.suse.com/1087493"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-7262"}],"related":["CVE-2018-7262"],"summary":"Security update for ceph","upstream":["CVE-2018-7262"]}