Advisory Published

USN-6259-1: Open-iSCSI vulnerabilities

First published: Thu Jul 27 2023(Updated: )

Jos Wetzels, Stanislav Dashevskyi, and Amine Amri discovered that Open-iSCSI incorrectly handled certain checksums for IP packets. An attacker could possibly use this issue to expose sensitive information. (CVE-2020-13987) Jos Wetzels, Stanislav Dashevskyi, Amine Amri discovered that Open-iSCSI incorrectly handled certain parsing TCP MSS options. An attacker could possibly use this issue to cause a crash or cause unexpected behavior. (CVE-2020-13988) Amine Amri and Stanislav Dashevskyi discovered that Open-iSCSI incorrectly handled certain TCP data. An attacker could possibly use this issue to expose sensitive information. (CVE-2020-17437)

Affected SoftwareAffected VersionHow to fix
All of
ubuntu/open-iscsi<2.0.874-7.1ubuntu6.4
2.0.874-7.1ubuntu6.4
=20.04
All of
ubuntu/open-iscsi<2.0.874-5ubuntu2.11+esm1
2.0.874-5ubuntu2.11+esm1
=18.04
All of
ubuntu/open-iscsi<2.0.873+git0.3b4b4500-14ubuntu3.7+esm1
2.0.873+git0.3b4b4500-14ubuntu3.7+esm1
=16.04

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Child vulnerabilities

(Contains the following vulnerabilities)

Frequently Asked Questions

  • What is the vulnerability ID for this Open-iSCSI vulnerability?

    The vulnerability ID for this Open-iSCSI vulnerability is CVE-2020-13987.

  • What is the severity of the Open-iSCSI vulnerability?

    The severity of the Open-iSCSI vulnerability is not mentioned in the information provided.

  • How can an attacker exploit the Open-iSCSI vulnerability?

    An attacker can exploit the Open-iSCSI vulnerability by using the incorrect handling of certain checksums for IP packets to expose sensitive information.

  • Which versions of Open-iSCSI are affected by this vulnerability?

    Open-iSCSI versions 2.0.874-7.1ubuntu6.4, 2.0.874-5ubuntu2.11+esm1, and 2.0.873+git0.3b4b4500-14ubuntu3.7+esm1 are affected by this vulnerability.

  • How can I fix the Open-iSCSI vulnerability?

    To fix the Open-iSCSI vulnerability, update the open-iscsi package to versions 2.0.874-7.1ubuntu6.4, 2.0.874-5ubuntu2.11+esm1, or 2.0.873+git0.3b4b4500-14ubuntu3.7+esm1, depending on your Ubuntu version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203