rpm package
suse/tcmu-runner&distro=SUSE Linux Enterprise Server 15-LTSS
pkg:rpm/suse/tcmu-runner&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSS
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-3139 | Hig | 8.1 | < 1.4.0-3.9.1 | 1.4.0-3.9.1 | Jan 13, 2021 | In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur |
- affected < 1.4.0-3.9.1fixed 1.4.0-3.9.1
In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur