VYPR

Open Iscsi

by Open Iscsi

Source repositories

CVEs (3)

  • CVE-2017-17840HigDec 27, 2017
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Open-iSCSI through 2.0.875. A local attacker can cause the iscsiuio server to abort or potentially execute code by sending messages with incorrect lengths, which (due to lack of checking) can lead to buffer overflows, and result in aborts (with…

  • CVE-2007-3099Jun 14, 2007
    risk 0.00cvss epss 0.01

    usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 checks the client's UID on the listening AF_LOCAL socket instead of the new connection, which allows remote attackers to access the management interface and cause a denial of service (iscsid exit or…

  • CVE-2007-3100Jun 14, 2007
    risk 0.00cvss epss 0.00

    usr/log.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 uses a semaphore with insecure permissions (world-writable/world-readable) for managing log messages using shared memory, which allows local users to cause a denial of service (hang) by grabbing the…