CVE-2016-5009
published 2016-07-12CVE-2016-5009: The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor…
PriorityP426medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
2.48%
82.8th percentile
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ceph | < ceph 10.2.5-1 (bookworm) | ceph 10.2.5-1 (bookworm) |
| redhat | ceph | <= 0.94.6 | — |
| redhat | ceph | >= 0 < 10.2.5-1 | 10.2.5-1 |
| redhat | ceph | >= 0 < 10.2.5-1 | 10.2.5-1 |
| redhat | ceph | >= 0 < 10.2.5-1 | 10.2.5-1 |
| redhat | ceph | >= 0 < 10.2.5-1 | 10.2.5-1 |
| redhat | ceph | >= 0 < 0.80.11-0ubuntu1.14.04.3 | 0.80.11-0ubuntu1.14.04.3 |
| redhat | ceph_storage_mon | — | — |
| redhat | ceph_storage_osd | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_for_scientific_computing | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2017-10-11·CVSS 6.5
CVE-2016-5009 [MEDIUM] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
It was discovered that Ceph incorrectly handled the handle_command
function. A remote authenticated user could use this issue to cause Ceph to
crash, resulting in a denial of service. (CVE-2016-5009)
Rahul Aggarwal discovered that Ceph incorrectly handled the
authenticated-read ACL. A remote attacker could possibly use this issue to
list bucket contents via a URL. (CVE-2016-7031)
Diluga Salome discovered that Ceph incorrectly handled certain POST objects
with null conditions. A remote attacker could possibly use this issue to
cuase Ceph to crash, resulting in a denial of service. (CVE-2016-8626)
Yang Liu discovered that Ceph incorrectly handled invalid HTTP Origin
headers. A remote attacker could possibly
Red Hat
crash: mon_command crashes ceph monitors on receiving empty prefix
vendor_redhat·2016-06-14·CVSS 6.5
CVE-2016-5009 [MEDIUM] CWE-20 crash: mon_command crashes ceph monitors on receiving empty prefix
crash: mon_command crashes ceph monitors on receiving empty prefix
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
A flaw was found in the way handle_command() function would validate prefix value from user. An authenticated attacker could send a specially crafted prefix value resulting in ceph monitor crash.
Package: ceph (Red Hat Enterprise Linux 6) - Not affected
Package: ceph-common (Red Hat Enterprise Linux 7) - Not affected
Package: ceph (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: ceph (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affected
Package: ceph (Red Hat Enterprise
Debian
CVE-2016-5009: ceph - The handle_command function in mon/Monitor.cc in Ceph allows remote authenticate...
vendor_debian·2016·CVSS 6.5
CVE-2016-5009 [MEDIUM] CVE-2016-5009: ceph - The handle_command function in mon/Monitor.cc in Ceph allows remote authenticate...
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
Scope: local
bookworm: resolved (fixed in 10.2.5-1)
bullseye: resolved (fixed in 10.2.5-1)
forky: resolved (fixed in 10.2.5-1)
sid: resolved (fixed in 10.2.5-1)
trixie: resolved (fixed in 10.2.5-1)
GHSA
GHSA-72p6-9489-jc3f: The handle_command function in mon/Monitor
ghsa_unreviewed·2022-05-17
CVE-2016-5009 [MEDIUM] CWE-20 GHSA-72p6-9489-jc3f: The handle_command function in mon/Monitor
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
OSV
ceph vulnerabilities
osv·2017-10-11·CVSS 6.5
CVE-2016-5009 [MEDIUM] ceph vulnerabilities
ceph vulnerabilities
It was discovered that Ceph incorrectly handled the handle_command
function. A remote authenticated user could use this issue to cause Ceph to
crash, resulting in a denial of service. (CVE-2016-5009)
Rahul Aggarwal discovered that Ceph incorrectly handled the
authenticated-read ACL. A remote attacker could possibly use this issue to
list bucket contents via a URL. (CVE-2016-7031)
Diluga Salome discovered that Ceph incorrectly handled certain POST objects
with null conditions. A remote attacker could possibly use this issue to
cuase Ceph to crash, resulting in a denial of service. (CVE-2016-8626)
Yang Liu discovered that Ceph incorrectly handled invalid HTTP Origin
headers. A remote attacker could possibly use this issue to cuase Ceph to
crash, resulting in a denial
OSV
CVE-2016-5009: The handle_command function in mon/Monitor
osv·2016-07-12·CVSS 6.5
CVE-2016-5009 [MEDIUM] CVE-2016-5009: The handle_command function in mon/Monitor
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-updates/2016-12/msg00126.htmlhttp://tracker.ceph.com/issues/16297https://access.redhat.com/errata/RHSA-2016:1384https://access.redhat.com/errata/RHSA-2016:1385https://github.com/ceph/ceph/commit/957ece7e95d8f8746191fd9629622d4457d690d6https://github.com/ceph/ceph/pull/9700http://lists.opensuse.org/opensuse-updates/2016-12/msg00126.htmlhttp://tracker.ceph.com/issues/16297https://access.redhat.com/errata/RHSA-2016:1384https://access.redhat.com/errata/RHSA-2016:1385https://github.com/ceph/ceph/commit/957ece7e95d8f8746191fd9629622d4457d690d6https://github.com/ceph/ceph/pull/9700
2016-07-12
Published