Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-0001
HistoryMar 15, 2011 - 12:00 a.m.

CVE-2011-0001

2011-03-1500:00:00
ubuntu.com
ubuntu.com
11

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.124

Percentile

95.4%

Double free vulnerability in the iscsi_rx_handler function
(usr/iscsi/iscsid.c) in the tgt daemon (tgtd) in Linux SCSI target
framework (tgt) before 1.0.14, aka scsi-target-utils, allows remote
attackers to cause a denial of service (memory corruption and crash) and
possibly execute arbitrary code via unknown vectors related to a buffer
overflow during iscsi login. NOTE: some of these details are obtained from
third party information.

Notes

Author Note
mdeslaur actually got fixed in 1.0.15
OSVersionArchitecturePackageVersionFilename
ubuntu10.10noarchtgt< 1:1.0.4-1ubuntu4.1UNKNOWN
ubuntu11.04noarchtgt< 1:1.0.13-0ubuntu2.1UNKNOWN
ubuntu11.10noarchtgt< 1:1.0.13-0ubuntu3UNKNOWN
ubuntu12.04noarchtgt< 1:1.0.13-0ubuntu3UNKNOWN
ubuntu12.10noarchtgt< 1:1.0.13-0ubuntu3UNKNOWN
ubuntu13.04noarchtgt< 1:1.0.13-0ubuntu3UNKNOWN
ubuntu13.10noarchtgt< 1:1.0.13-0ubuntu3UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.124

Percentile

95.4%