rpm package
opensuse/tcmu-runner&distro=openSUSE Leap 15.1
pkg:rpm/opensuse/tcmu-runner&distro=openSUSE%20Leap%2015.1
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-3139 | Hig | 8.1 | < 1.4.0-lp151.3.9.1 | 1.4.0-lp151.3.9.1 | Jan 13, 2021 | In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur |
- affected < 1.4.0-lp151.3.9.1fixed 1.4.0-lp151.3.9.1
In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur