Vulnerability CVE-2018-1129: Information

Description

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

Severity: MEDIUM (6.5) Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Published: July 10, 2018
Modified: Aug. 29, 2019
Error type identifier: CWE-287

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
cephsisyphus12.2.8-alt1.S118.2.1-alt2.1ALT-PU-2018-2306-1212719Fixed
cephp1012.2.8-alt1.S117.2.7-alt2ALT-PU-2018-2306-1212719Fixed
cephp912.2.8-alt1.S114.2.22-alt1ALT-PU-2018-2306-1212719Fixed
cephp812.2.8-alt1.M80P.112.2.13-alt1ALT-PU-2018-2342-1212810Fixed
cephc10f112.2.8-alt1.S117.2.6-alt2ALT-PU-2018-2306-1212719Fixed
cephc9f212.2.8-alt1.S114.2.22-alt1ALT-PU-2018-2306-1212719Fixed
cephc710.2.11-alt1.M70C.210.2.11-alt1.M70C.2ALT-PU-2019-1725-1218597Fixed
kernel-image-std-debugsisyphus4.14.86-alt16.1.87-alt1ALT-PU-2018-2795-1217397Fixed
kernel-image-std-debugc9f24.14.86-alt14.19.102-alt1ALT-PU-2018-2795-1217397Fixed
kernel-image-std-defsisyphus4.14.86-alt16.1.87-alt1ALT-PU-2018-2796-1217398Fixed
kernel-image-std-defp104.14.86-alt15.10.213-alt1ALT-PU-2018-2796-1217398Fixed
kernel-image-std-defp94.14.86-alt15.4.274-alt1ALT-PU-2018-2796-1217398Fixed
kernel-image-std-defp84.9.144-alt0.M80P.14.9.337-alt0.M80P.1ALT-PU-2018-2833-1217715Fixed
kernel-image-std-defc9f24.14.86-alt15.10.214-alt0.c9f.2ALT-PU-2018-2796-1217398Fixed
kernel-image-std-paec9f24.14.86-alt14.19.72-alt1ALT-PU-2018-2814-1217123Fixed
kernel-image-un-defp84.14.87-alt0.M80P.14.19.310-alt0.M80P.1ALT-PU-2018-2832-1217631Fixed
kernel-image-un-defc74.9.277-alt0.M70C.14.9.277-alt0.M70C.1ALT-PU-2021-3032-1281292Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:ceph_storage_osd:2:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:ceph_storage_mon:2:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:ceph_storage:3:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:ceph_storage_osd:3:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:ceph_storage_mon:3:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:ceph_storage:1.3:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:a:ceph:ceph:12.2.1:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:13.2.1:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:13.2.0:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:12.2.7:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:12.2.6:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:12.2.5:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:12.2.4:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:12.2.3:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:12.2.2:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:12.2.0:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:10.2.11:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:10.2.10:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:10.2.9:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:10.2.8:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:10.2.7:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:10.2.6:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:10.2.5:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:10.2.4:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:10.2.3:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:10.2.2:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:10.2.1:*:*:*:*:*:*:*

      cpe:2.3:a:ceph:ceph:10.2.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*