—
PYSEC-2015-3
Quick fix
PYSEC-2015-3 — ceph-deploy: upgrade to the fixed version with the command below.
pip install --upgrade 'ceph-deploy>=1.5.23'Details
The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- http://tracker.ceph.com/issues/11694[WEB]
- http://www.openwall.com/lists/oss-security/2015/04/09/9[WEB]
- http://www.openwall.com/lists/oss-security/2015/05/22/1[WEB]
- http://www.securityfocus.com/bid/74775[WEB]
- http://rhn.redhat.com/errata/RHSA-2015-1092.html[ADVISORY]
- https://github.com/advisories/GHSA-79jf-ccm8-43w7[ADVISORY]