Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-0743

Опубликовано: 22 мар. 2010
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5scsi-target-utilsAffected
Red Hat Enterprise Linux 6scsi-target-utilsNot affected
Red Hat Enterprise Linux 5scsi-target-utilsFixedRHSA-2010:036220.04.2010

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-134
https://bugzilla.redhat.com/show_bug.cgi?id=576359scsi-target-utils: format string vulnerability

EPSS

Процентиль: 91%
0.06442
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 15 лет назад

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.

nvd
около 15 лет назад

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.

debian
около 15 лет назад

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI tar ...

github
около 3 лет назад

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.

oracle-oval
около 15 лет назад

ELSA-2010-0362: scsi-target-utils security update (IMPORTANT)

EPSS

Процентиль: 91%
0.06442
Низкий

4.3 Medium

CVSS2