scsi-target-utils: format string vulnerability
Published Apr 8, 2010
5.0
MEDIUMCVSS 2.0
EPSS 3.38%
Description
Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.
Affected products
No data.
Configuration 2
- 0.4.16
No data.
Red Hat Enterprise Linux 5
scsi-target-utils-0:0.0-6.20091205snap.el5_5.2
Fixed · RHSA-2010:0362
Red Hat Enterprise Linux 5
scsi-target-utils
Affected
Red Hat Enterprise Linux 6
scsi-target-utils
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | scsi-target-utils-0:0.0-6.20091205snap.el5_5.2 | Fixed | RHSA-2010:0362 |
| Red Hat Enterprise Linux 5 | scsi-target-utils | Affected | n/a |
| Red Hat Enterprise Linux 6 | scsi-target-utils | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.38% (0.03381) | 88.39th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.38% (0.03381) | 87.19th | v5 (v2026.06.15) |
| Mar 30, 2025 | 6.44% (0.06442) | 90.13th | v4 (v2025.03.14) |
| Mar 29, 2025 | 14.03% (0.14032) | 90.59th | v4 (v2025.03.14) |
| Mar 19, 2025 | 6.44% (0.06442) | 89.88th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.68% (0.04683) | 88.61th | v4 (v2025.03.14) |
| Dec 12, 2024 | 65.75% (0.65754) | 98.03th | v3 (v2023.03.01) |
| Mar 7, 2023 | 65.75% (0.65754) | 97.29th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.78% (0.03779) | 85.48th | v2 (v2022.01.01) |
| Feb 13, 2023 | 3.78% (0.03779) | 85.08th | v2 (v2022.01.01) |
| Feb 3, 2023 | 2.69% (0.02686) | 82.44th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.78% (0.03779) | 84.01th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.78% (0.03779) | 67.21th | v2 (v2022.01.01) |
References (16)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=574935 x_refsource_CONFIRMPatch
- http://git.kernel.org/?p=linux/kernel/git/tomo/tgt.git%3Ba=commit%3Bh=107d922706cd36f3bb79bcca9bc4678c32f22e59 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=oss-security&m=127005132403189&w=2 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/39142 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/39726 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2010/dsa-2042 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:131 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/bid/39127 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2010/1786 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-0743 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=576359 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57496 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2010-0743
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11248 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2010-0743
Change history (0)
No recorded changes yet.