2024-06-28 13:17:52 +00:00
{
"Definition" : [
{
"ID" : "oval:org.altlinux.errata:def:20172790" ,
"Version" : "oval:org.altlinux.errata:def:20172790" ,
"Class" : "patch" ,
"Metadata" : {
"Title" : "ALT-PU-2017-2790: package `ceph` update to version 12.2.2-alt1.S1" ,
"AffectedList" : [
{
"Family" : "unix" ,
"Platforms" : [
"ALT Linux branch c9f2"
] ,
"Products" : [
"ALT SPWorkstation" ,
"ALT SPServer"
]
}
] ,
"References" : [
{
"RefID" : "ALT-PU-2017-2790" ,
"RefURL" : "https://errata.altlinux.org/ALT-PU-2017-2790" ,
"Source" : "ALTPU"
} ,
{
"RefID" : "CVE-2017-16818" ,
"RefURL" : "https://nvd.nist.gov/vuln/detail/CVE-2017-16818" ,
"Source" : "CVE"
}
] ,
"Description" : "This update upgrades ceph to version 12.2.2-alt1.S1. \nSecurity Fix(es):\n\n * CVE-2017-16818: RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging \"full\" (not necessarily admin) privileges to post an invalid profile to the admin API, related to rgw/rgw_iam_policy.cc, rgw/rgw_basic_types.h, and rgw/rgw_iam_types.h." ,
"Advisory" : {
"From" : "errata.altlinux.org" ,
"Severity" : "Low" ,
"Rights" : "Copyright 2024 BaseALT Ltd." ,
"Issued" : {
"Date" : "2017-12-11"
} ,
"Updated" : {
"Date" : "2017-12-11"
} ,
"BDUs" : null ,
"CVEs" : [
{
"ID" : "CVE-2017-16818" ,
"CVSS" : "AV:N/AC:L/Au:S/C:N/I:N/A:P" ,
"CVSS3" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" ,
"CWE" : "CWE-617" ,
"Href" : "https://nvd.nist.gov/vuln/detail/CVE-2017-16818" ,
"Impact" : "Low" ,
"Public" : "20171220"
}
] ,
"AffectedCPEs" : {
"CPEs" : [
"cpe:/o:alt:spworkstation:8.4" ,
"cpe:/o:alt:spserver:8.4"
]
}
}
} ,
"Criteria" : {
"Operator" : "AND" ,
"Criterions" : [
{
2024-12-12 21:07:30 +00:00
"TestRef" : "oval:org.altlinux.errata:tst:4001" ,
2024-06-28 13:17:52 +00:00
"Comment" : "ALT Linux must be installed"
}
] ,
"Criterias" : [
{
"Operator" : "OR" ,
"Criterions" : [
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790001" ,
"Comment" : "ceph is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790002" ,
"Comment" : "ceph-base is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790003" ,
"Comment" : "ceph-common is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790004" ,
"Comment" : "ceph-devel is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790005" ,
"Comment" : "ceph-fuse is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790006" ,
"Comment" : "ceph-mds is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790007" ,
"Comment" : "ceph-mgr is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790008" ,
"Comment" : "ceph-mon is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790009" ,
"Comment" : "ceph-osd is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790010" ,
"Comment" : "ceph-radosgw is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790011" ,
"Comment" : "ceph-resource-agents is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790012" ,
"Comment" : "ceph-test is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790013" ,
"Comment" : "libcephfs2 is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790014" ,
"Comment" : "libcephfs2-devel is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790015" ,
"Comment" : "librados2 is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790016" ,
"Comment" : "librados2-devel is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790017" ,
"Comment" : "libradosstriper1 is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790018" ,
"Comment" : "libradosstriper1-devel is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790019" ,
"Comment" : "librbd1 is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790020" ,
"Comment" : "librbd1-devel is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790021" ,
"Comment" : "librgw2 is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790022" ,
"Comment" : "librgw2-devel is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790023" ,
"Comment" : "python-module-ceph is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790024" ,
"Comment" : "python-module-ceph-argparse is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790025" ,
"Comment" : "python-module-ceph_detect_init is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790026" ,
"Comment" : "python-module-ceph_disk is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790027" ,
"Comment" : "python-module-ceph_volume is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790028" ,
"Comment" : "python-module-cephfs is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790029" ,
"Comment" : "python-module-rados is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790030" ,
"Comment" : "python-module-rbd is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790031" ,
"Comment" : "python-module-rgw is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790032" ,
"Comment" : "python3-module-ceph is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790033" ,
"Comment" : "python3-module-ceph-argparse is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790034" ,
"Comment" : "python3-module-cephfs is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790035" ,
"Comment" : "python3-module-rados is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790036" ,
"Comment" : "python3-module-rbd is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790037" ,
"Comment" : "python3-module-rgw is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790038" ,
"Comment" : "rbd-fuse is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790039" ,
"Comment" : "rbd-mirror is earlier than 0:12.2.2-alt1.S1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20172790040" ,
"Comment" : "rbd-nbd is earlier than 0:12.2.2-alt1.S1"
}
]
}
]
}
}
]
}