-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ceph-deploy security update Advisory ID: RHSA-2015:1092-01 Product: Red Hat Ceph Storage Advisory URL: https://access.redhat.com/errata/RHSA-2015:1092 Issue date: 2015-06-11 CVE Names: CVE-2015-3010 CVE-2015-4053 ===================================================================== 1. Summary: An updated ceph-deploy package that fixes two security issues is now available for Red Hat Ceph Storage. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Ceph Storage Installer 1.2 - noarch 3. Description: Red Hat Ceph Storage is a massively scalable, open, software-defined storage platform that combines the most stable version of Ceph with a Ceph management platform, deployment tools, and support services. It was discovered that ceph-deploy, a utility for deploying Red Hat Ceph Storage, would create the keyring file with world readable permissions, which could possibly allow a local user to obtain authentication credentials from the keyring file. (CVE-2015-3010, CVE-2015-4053) All ceph-deploy users are advised to upgrade to this updated package, which contains backported patches to correct these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1210705 - CVE-2015-3010 ceph-deploy: keyring permissions are world readable in ~ceph 1224129 - CVE-2015-4053 ceph-deploy admin command copies keyring file to /etc/ceph which is world readable 6. Package List: Red Hat Ceph Storage Installer 1.2: Source: ceph-deploy-1.5.22-0.4.rc1.el6cp.src.rpm noarch: ceph-deploy-1.5.22-0.4.rc1.el6cp.noarch.rpm Red Hat Ceph Storage Installer 1.2: Source: ceph-deploy-1.5.22-0.4.rc1.el7cp.src.rpm noarch: ceph-deploy-1.5.22-0.4.rc1.el7cp.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-3010 https://access.redhat.com/security/cve/CVE-2015-4053 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVebfsXlSAg2UNWIIRAjpTAKCzHY7LXyJbb6QBZKvn2PTeCoR8eQCfegL8 wJ9EFaCP1YQC8MZ2TSENY7E= =mqgH -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce