Back

MEDIUM

scsi-target-utils: double-free vulnerability leads to pre-authenticated crash

Published Mar 15, 2011

Description

Double free vulnerability in the iscsi_rx_handler function (usr/iscsi/iscsid.c) in the tgt daemon (tgtd) in Linux SCSI target framework (tgt) before 1.0.14, aka scsi-target-utils, allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown vectors related to a buffer overflow during iscsi login. NOTE: some of these details are obtained from third party information.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 15, 2011
Updated Aug 6, 2024
Reserved Dec 7, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Mar 9, 2011