Back

MEDIUM

scsi-target-utils: stack buffer overflow vulnerability

Published Jul 8, 2010

Description

Multiple buffer overflows in the iSNS implementation in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) before 1.0.6, (2) iSCSI Enterprise Target (aka iscsitarget or IET) 1.4.20.1 and earlier, and (3) Generic SCSI Target Subsystem for Linux (aka SCST or iscsi-scst) 1.0.1.1 and earlier allow remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via (a) a long iSCSI Name string in an SCN message or (b) an invalid PDU.

Affected products

Remediation

No remediation recorded yet.

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 8, 2010
Updated Aug 7, 2024
Reserved Jun 9, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jul 1, 2010