In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesnt handle malformed HTTP headers properly, allowing for denial of service.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ceph | Redhat | * | 12.2.3 (excluding) |
Ceph | Redhat | 13.0.0 (including) | 13.0.0 (including) |
Ceph | Redhat | 13.0.1 (including) | 13.0.1 (including) |
Red Hat Ceph Storage 3.0 | RedHat | ceph-2:12.2.1-46.el7cp | * |
Red Hat Ceph Storage 3 for Ubuntu | RedHat | * |