[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252212

 
 

909

 
 

196748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2017-17840 -- open-iscsi

ID: oval:org.secpod.oval:def:2000341Date: (C)2019-06-02   (M)2021-06-02
Class: VULNERABILITYFamily: unix




An issue was discovered in Open-iSCSI through 2.0.875. A local attacker can cause the iscsiuio server to abort or potentially execute code by sending messages with incorrect lengths, which can lead to buffer overflows, and result in aborts or code execution. The process_iscsid_broadcast function in iscsiuio/src/unix/iscsid_ipc.c does not validate the payload length before a write operation.

Platform:
Debian 8.x
Debian 9.x
Product:
open-iscsi
Reference:
CVE-2017-17840
CVE    1
CVE-2017-17840
CPE    3
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/a:gnu:open-iscsi

© SecPod Technologies