Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-0743

Опубликовано: 08 апр. 2010
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:zaal:tgt:*:*:*:*:*:*:*:*
Версия до 0.9.5 (включая)
cpe:2.3:a:zaal:tgt:1.0.3:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:iscsitarget:iscsitarget:0.4.16:*:*:*:*:*:*:*

EPSS

Процентиль: 91%
0.06442
Низкий

5 Medium

CVSS2

Дефекты

CWE-134

Связанные уязвимости

ubuntu
больше 15 лет назад

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.

redhat
больше 15 лет назад

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.

debian
больше 15 лет назад

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI tar ...

github
больше 3 лет назад

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.

oracle-oval
больше 15 лет назад

ELSA-2010-0362: scsi-target-utils security update (IMPORTANT)

EPSS

Процентиль: 91%
0.06442
Низкий

5 Medium

CVSS2

Дефекты

CWE-134