MEDIUM · 5.0

CVE-2010-2221

Multiple buffer overflows in the iSNS implementation in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) before 1.0.6, (2) iSCSI Enterprise Target (aka iscsitarget or IET) 1.4....

Vulnerability Description

Multiple buffer overflows in the iSNS implementation in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) before 1.0.6, (2) iSCSI Enterprise Target (aka iscsitarget or IET) 1.4.20.1 and earlier, and (3) Generic SCSI Target Subsystem for Linux (aka SCST or iscsi-scst) 1.0.1.1 and earlier allow remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via (a) a long iSCSI Name string in an SCN message or (b) an invalid PDU.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
ZaalTgt<= 1.0.5
LinuxLinux KernelAll versions
Arne Redlich \& Ross WalkerIscsitarget<= 1.4.20
Vladislav BolkhovitinGeneric Scsi Target Subsystem<= 1.0.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-2221?

CVE-2010-2221 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Multiple buffer overflows in the iSNS implementation in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) before 1.0.6, (2) iSCSI Enterprise Target (aka iscsitarget or IET) 1.4....

How severe is CVE-2010-2221?

CVE-2010-2221 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-2221?

Check the references section above for vendor advisories and patch information. Affected products include: Zaal Tgt, Linux Linux Kernel, Arne Redlich \& Ross Walker Iscsitarget, Vladislav Bolkhovitin Generic Scsi Target Subsystem.