[Forgot Password]
Login  Register Subscribe

23631

 
 

117687

 
 

98250

 
 

909

 
 

79198

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2010-2221

Date: (C)2010-07-08   (M)2017-11-18 


Multiple buffer overflows in the iSNS implementation in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) before 1.0.6, (2) iSCSI Enterprise Target (aka iscsitarget or IET) 1.4.20.1 and earlier, and (3) Generic SCSI Target Subsystem for Linux (aka SCST or iscsi-scst) 1.0.1.1 and earlier allow remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via (a) a long iSCSI Name string in an SCN message or (b) an invalid PDU.

CVSS Score: 5.0Access Vector: NETWORK
Exploit Score: 10.0Access Complexity: LOW
Impact Score: 2.9Authentication: NONE
 Confidentiality: NONE
 Integrity: NONE
 Availability: PARTIAL





Reference:
SECTRACK-1024175
http://archives.neohapsis.com/archives/bugtraq/2010-07/0022.html
SECUNIA-40485
SECUNIA-40494
SECUNIA-40495
BID-41327
OSVDB-65990
OSVDB-65991
OSVDB-65992
ADV-2010-1760
ADV-2010-1786
MDVSA-2010:131
RHSA-2010:0518
SUSE-SR:2010:017
http://sourceforge.net/mailarchive/forum.php?thread_name=E2BB8074E5500C42984D980D4BD78EF904075006%40MFG-NYC-EXCH2.mfg.prv&forum_name=iscsitarget-devel
http://lists.wpkg.org/pipermail/stgt/2010-July/003858.html
http://scst.svn.sourceforge.net/viewvc/scst/trunk/iscsi-scst/usr/isns.c?r1=1793&r2=1792&pathrev=1793
http://scst.svn.sourceforge.net/viewvc/scst?view=revision&revision=1793
https://bugzilla.redhat.com/show_bug.cgi?id=593877

CWE    1
CWE-119
OVAL    4
oval:org.secpod.oval:def:201778
oval:org.secpod.oval:def:201934
oval:org.secpod.oval:def:102737
oval:org.secpod.oval:def:700537
...

© 2013 SecPod Technologies