SuSE Linux Kernel Unauthorized SCSI Command Vulnerability
BID:11784
Info
SuSE Linux Kernel Unauthorized SCSI Command Vulnerability
| Bugtraq ID: | 11784 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-1190 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 01 2004 12:00AM |
| Updated: | Aug 05 2010 07:46PM |
| Credit: | The individual or individuals responsible for disclosure of this issue are currently unknown; this issue was disclosed in the referenced vendor advisory. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE Linux 8.1 SuSE Linux 9 S.u.S.E. Linux Personal 9.1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 |
| Not Vulnerable: | |
Discussion
SuSE Linux Kernel Unauthorized SCSI Command Vulnerability
SuSE Linux is reported susceptible to an unauthorized SCSI command vulnerability.
Malicious users may be able to send commands to SCSI devices that result in the overwriting of their firmware. This potentially results in the failure of the targeted device to further operate. This may result in the permanent, unrecoverable destruction of SCSI devices, requiring that they be sent to the vendor for service or replacement.
SuSE Linux 9.1, and SuSE Linux Enterprise Server 9 are reported to be vulnerable to this issue. Other versions, and other distributions of Linux are also potentially affected.
SuSE Linux is reported susceptible to an unauthorized SCSI command vulnerability.
Malicious users may be able to send commands to SCSI devices that result in the overwriting of their firmware. This potentially results in the failure of the targeted device to further operate. This may result in the permanent, unrecoverable destruction of SCSI devices, requiring that they be sent to the vendor for service or replacement.
SuSE Linux 9.1, and SuSE Linux Enterprise Server 9 are reported to be vulnerable to this issue. Other versions, and other distributions of Linux are also potentially affected.
Exploit / POC
SuSE Linux Kernel Unauthorized SCSI Command Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SuSE Linux Kernel Unauthorized SCSI Command Vulnerability
Solution:
SuSE Linux has released advisory SUSE-SA:2004:042 along with fixes to address this issue. Please see the referenced advisory for further information.
Red Hat has released advisory RHSA-2006:0101-9, along with fixes to address various Linux Kernel issues in Red Hat Enterprise Linux 4 operating systems. Please see the referenced advisory for further information.
Solution:
SuSE Linux has released advisory SUSE-SA:2004:042 along with fixes to address this issue. Please see the referenced advisory for further information.
Red Hat has released advisory RHSA-2006:0101-9, along with fixes to address various Linux Kernel issues in Red Hat Enterprise Linux 4 operating systems. Please see the referenced advisory for further information.
References
SuSE Linux Kernel Unauthorized SCSI Command Vulnerability
References:
References: