RHSA-2010:0518: Important: scsi-target-utils security update
The scsi-target-utils package contains the daemon and tools to set up andmonitor SCSI targets. Currently, iSCSI software and iSER targets aresupported.Multiple buffer overflow flaws were found in scsi-target-utils' tgtddaemon. A remote attacker could trigger these flaws by sending acarefully-crafted Internet Storage Name Service (iSNS) request, causing thetgtd daemon to crash. (CVE-2010-2221)Red Hat would like to thank the Vulnerability Research Team at TELUSSecurity Labs and Fujita Tomonori for responsibly reporting these flaws.All scsi-target-utils users should upgrade to this updated package, whichcontains a backported patch to correct these issues. All runningscsi-target-utils services must be restarted for the update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0518?
The severity of RHSA-2010:0518 is classified as important.
How do I fix RHSA-2010:0518?
To fix RHSA-2010:0518, update the scsi-target-utils package to version 0.0-6.20091205snap.el5_5.3 or later.
What vulnerabilities are addressed by RHSA-2010:0518?
RHSA-2010:0518 addresses multiple buffer overflow flaws in the scsi-target-utils package.
Who is affected by RHSA-2010:0518?
Users of the scsi-target-utils package up to version 0.0-6.20091205snap.el5_5.3 are affected by RHSA-2010:0518.
What is the risk of not addressing RHSA-2010:0518?
Not addressing RHSA-2010:0518 could allow remote attackers to exploit buffer overflow vulnerabilities, potentially compromising the system.