VYPR

rpm package

suse/tcmu-runner&distro=SUSE Linux Enterprise Module for Server Applications 15 SP2

pkg:rpm/suse/tcmu-runner&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2

Vulnerabilities (1)

  • CVE-2021-3139HigJan 13, 2021
    affected < 1.5.2-3.3.1fixed 1.5.2-3.3.1

    In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur