CVE-2011-0001: Buffer Overflow
Double free vulnerability in the iscsirxhandler function (usr/iscsi/iscsid.c) in the tgt daemon (tgtd) in Linux SCSI target framework (tgt) before 1.0.14, aka scsi-target-utils, allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown vectors related to a buffer overflow during iscsi login. NOTE: some of these details are obtained from third party information.
Other sources
Emmanuel Bouillon reported a double-free flaw in scsi-target-utils that could cause the tgtd daemon to crash with memory corruption on receipt of certain network traffic, leading to a denial of service condition.
Acknowledgements:
Red Hat would like to thank Emmanuel Bouillon of NATO C3 Agency for reporting this issue.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0001?
The severity of CVE-2011-0001 is high due to the potential for remote attackers to cause a denial of service and possibly execute arbitrary code.
How do I fix CVE-2011-0001?
To fix CVE-2011-0001, upgrade the tgt daemon to version 1.0.14 or later.
Which versions of tgt are affected by CVE-2011-0001?
CVE-2011-0001 affects tgt versions before 1.0.14, including 0.9.5, 1.0.0, 1.0.1, and up to 1.0.13.
What kind of vulnerability is CVE-2011-0001?
CVE-2011-0001 is classified as a double free vulnerability that leads to memory corruption.
What impact does CVE-2011-0001 have on systems?
CVE-2011-0001 can lead to system crashes and denial of service, compromising the stability of affected systems.