PT-2021-27320 · Unknown · Open-Iscsi
Published
2021-01-16
·
Updated
2021-01-16
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions:
open-iscsi versions prior to 2.1.3
Description:
The issue concerns multiple problems in the open-iscsi package, including checks for TCP urgent pointer past end of frame, u8 overflow when processing TCP options, header length underflow during checksum calculation, memory leaks, and NULL pointer dereferences. Additionally, there are fixes for illegal memory access, optimization of mode parameter verification, and fixes for logging levels. The update also includes async login ability and fixes for buffer overflow regressions.
Recommendations:
For open-iscsi versions prior to 2.1.3, update to version 2.1.3 or later to resolve the issues.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open-Iscsi