PT-2007-1028 · Debian+1 · Open-Iscsi+1
Olaf Kirch
·
Published
2007-06-14
·
Updated
2017-10-11
·
CVE-2007-3100
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
open-iscsi versions prior to 2.0-865
Description:
The issue concerns multiple vulnerabilities in the open-iscsi package of the Debian GNU/Linux operating system. These vulnerabilities can be exploited by a local attacker, potentially leading to a denial of service, which disrupts the availability of protected information. Specifically, the
usr/log.c file in iscsid uses a semaphore with insecure permissions for managing log messages, allowing local users to cause a denial of service by grabbing the semaphore.Recommendations:
For open-iscsi versions prior to 2.0-865, consider updating to version 2.0-865 or later to resolve the issue. As a temporary workaround, consider restricting access to the
usr/log.c file in iscsid to prevent local users from exploiting the vulnerability. Additionally, restrict the use of the semaphore used for managing log messages to minimize the risk of a denial of service.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Open-Iscsi