Open ISCSI Multiple Local Denial Of Service Vulnerabilities
BID:24471
Info
Open ISCSI Multiple Local Denial Of Service Vulnerabilities
| Bugtraq ID: | 24471 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-3099 CVE-2007-3100 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 14 2007 12:00AM |
| Updated: | Mar 19 2015 08:46AM |
| Credit: | Olaf Kirch from Oracle is credited with the discovery of these issues. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise Desktop 10 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc Red Hat Fedora 7 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Open-iSCSI Open-iSCSI 0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Open ISCSI Multiple Local Denial Of Service Vulnerabilities
Open-iSCSI is prone to multiple local denial-of-service vulnerabilities.
A local attacker can exploit these issues to deny legitimate user access to the server daemon.
Open-iSCSI is prone to multiple local denial-of-service vulnerabilities.
A local attacker can exploit these issues to deny legitimate user access to the server daemon.
Exploit / POC
Open ISCSI Multiple Local Denial Of Service Vulnerabilities
To exploit these issues an attacker must have local interactive access to a computer running the affected application.
To exploit these issues an attacker must have local interactive access to a computer running the affected application.
Solution / Fix
Open ISCSI Multiple Local Denial Of Service Vulnerabilities
Solution:
Please see the references for more information.
Solution:
Please see the references for more information.
References
Open ISCSI Multiple Local Denial Of Service Vulnerabilities
References:
References:
- Vendor Homepage (Open-iSCSI)
- RHSA-2007:0497-2 iscsi-initiator-utils security update (Red hat)