Skip to main content

Linux Kernel iSCSI Heap Overflow Vulnerability

Last Update Date: 4 Jun 2013 10:22 Release Date: 4 Jun 2013 3509 Views

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

A vulnerability was identified in the Linux Kernel. A remote user can execute arbitrary code on the target system.

 

On systems with an iSCSI target configured and listening on the network, a remote user can send specially crafted data to trigger a buffer overflow and execute arbitrary code on the target system. The code will run with the privileges of the target service.

 

The vulnerability resides in 'drivers/target/iscsi/iscsi_target_parameters.c'.


Impact

  • Remote Code Execution

System / Technologies affected

  • Version prior to 3.8.9

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link