RHSA-2010:0362: Important: scsi-target-utils security update
The scsi-target-utils package contains the daemon and tools to set up andmonitor SCSI targets. Currently, iSCSI software and iSER targets aresupported.A format string flaw was found in scsi-target-utils' tgtd daemon. Aremote attacker could trigger this flaw by sending a carefully-craftedInternet Storage Name Service (iSNS) request, causing the tgtd daemon tocrash. (CVE-2010-0743)All scsi-target-utils users should upgrade to this updated package, whichcontains a backported patch to correct this issue. All runningscsi-target-utils services must be restarted for the update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0362?
The severity of RHSA-2010:0362 is classified as important.
How do I fix RHSA-2010:0362?
To fix RHSA-2010:0362, update the scsi-target-utils package to version 0.0-6.20091205snap.el5_5.2.
What is the impact of the vulnerability in RHSA-2010:0362?
The impact of the vulnerability in RHSA-2010:0362 could allow a remote attacker to execute arbitrary code.
Which systems are affected by RHSA-2010:0362?
Systems running scsi-target-utils version up to 0.0-6.20091205snap.el5_5.2 are affected by RHSA-2010:0362.
What does the flaw in RHSA-2010:0362 relate to?
The flaw in RHSA-2010:0362 relates to a format string vulnerability in the tgtd daemon.