[DSA 4339-1] ceph security update

DSA-4339-1 ceph
2018-11-13
CVE-2017-7519 CVE-2018-10861 CVE-2018-1128 CVE-2018-1129
ceph
<define-tag isvulnerable>yes</define-tag>
<define-tag fixed>yes</define-tag>
<define-tag fixed-section>no</define-tag>
security update
<define-tag moreinfo>
<p>Multiple vulnerabilities were discovered in Ceph, a distributed storage
and file system: The cephx authentication protocol was suspectible to
replay attacks and calculated signatures incorrectly, <q>ceph mon</q> did not
validate capabilities for pool operations (resulting in potential
corruption or deletion of snapshot images) and a format string
vulnerability in libradosstriper could result in denial of service.</p>
<p>For the stable distribution (stretch), these problems have been fixed in
version 10.2.11-1.</p>
<p>We recommend that you upgrade your ceph packages.</p>
<p>For the detailed security status of ceph please refer to
its security tracker page at:
<a href=""></a></p>
