In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/99075 | vdb entry third party advisory |
https://www.debian.org/security/2018/dsa-4339 | third party advisory vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7519 | issue tracking exploit vendor advisory |