Bugzilla – Bug 1069253
VUL-0: CVE-2017-16818: ceph: Failed assertion through user input
Last modified: 2018-01-11 20:25:00 UTC
rh#1515872 A flaw was discovered in ceph. Assertion in rgw_iam_policy.cc can be reached by user input and fail through data passed in from a rest call causing it to crash. Upstream patch: https://github.com/ceph/ceph/commit/b3118cabb8060a8cc6a01c4e8264cb18e7b1745a References: https://bugzilla.redhat.com/show_bug.cgi?id=1515872 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16818 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16818
@Johannes, is this the same as Bug 1063014 ?
(In reply to Nathan Cutler from comment #1) yes, I knew this looked familiar but I couldn't place it anymore. Thanks for the hint
as remembered by Nathan *** This bug has been marked as a duplicate of bug 1063014 ***