PT-2007-1028 · Debian+1 · Open-Iscsi+1
Olaf Kirch
·
Publicado
2007-06-14
·
Atualizado
2017-10-11
·
CVE-2007-3100
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
open-iscsi versions prior to 2.0-865
Description:
The issue concerns multiple vulnerabilities in the open-iscsi package of the Debian GNU/Linux operating system. These vulnerabilities can be exploited by a local attacker, potentially leading to a denial of service, which disrupts the availability of protected information. Specifically, the
usr/log.c file in iscsid uses a semaphore with insecure permissions for managing log messages, allowing local users to cause a denial of service by grabbing the semaphore.Recommendations:
For open-iscsi versions prior to 2.0-865, consider updating to version 2.0-865 or later to resolve the issue. As a temporary workaround, consider restricting access to the
usr/log.c file in iscsid to prevent local users from exploiting the vulnerability. Additionally, restrict the use of the semaphore used for managing log messages to minimize the risk of a denial of service.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat
Open-Iscsi