First published: Thu Jul 08 2010(Updated: )
The scsi-target-utils package contains the daemon and tools to set up and<br>monitor SCSI targets. Currently, iSCSI software and iSER targets are<br>supported.<br>Multiple buffer overflow flaws were found in scsi-target-utils' tgtd<br>daemon. A remote attacker could trigger these flaws by sending a<br>carefully-crafted Internet Storage Name Service (iSNS) request, causing the<br>tgtd daemon to crash. (CVE-2010-2221)<br>Red Hat would like to thank the Vulnerability Research Team at TELUS<br>Security Labs and Fujita Tomonori for responsibly reporting these flaws.<br>All scsi-target-utils users should upgrade to this updated package, which<br>contains a backported patch to correct these issues. All running<br>scsi-target-utils services must be restarted for the update to take effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/scsi-target-utils | <0.0-6.20091205snap.el5_5.3 | 0.0-6.20091205snap.el5_5.3 |
redhat/scsi-target-utils | <0.0-6.20091205snap.el5_5.3 | 0.0-6.20091205snap.el5_5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.