Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-0743

Опубликовано: 08 апр. 2010
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:zaal:tgt:*:*:*:*:*:*:*:*
Версия до 0.9.5 (включая)
cpe:2.3:a:zaal:tgt:1.0.3:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:iscsitarget:iscsitarget:0.4.16:*:*:*:*:*:*:*

EPSS

Процентиль: 91%
0.06442
Низкий

5 Medium

CVSS2

Дефекты

CWE-134

Связанные уязвимости

ubuntu
около 15 лет назад

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.

redhat
больше 15 лет назад

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.

debian
около 15 лет назад

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI tar ...

github
около 3 лет назад

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.

oracle-oval
около 15 лет назад

ELSA-2010-0362: scsi-target-utils security update (IMPORTANT)

EPSS

Процентиль: 91%
0.06442
Низкий

5 Medium

CVSS2

Дефекты

CWE-134