Linux Kernel iSCSI Heap Overflow Vulnerability
RISK: Medium Risk
TYPE: Operating Systems - Linux
A vulnerability was identified in the Linux Kernel. A remote user can execute arbitrary code on the target system.
On systems with an iSCSI target configured and listening on the network, a remote user can send specially crafted data to trigger a buffer overflow and execute arbitrary code on the target system. The code will run with the privileges of the target service.
The vulnerability resides in 'drivers/target/iscsi/iscsi_target_parameters.c'.
Impact
- Remote Code Execution
System / Technologies affected
- Version prior to 3.8.9
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a source code fix, available at:
http://git.kernel.org/cgit/linux/kernel/git/nab/target-pending.git/commit/?id=cea4dcfdad926a27a18e188720efe0f2c9403456
Vulnerability Identifier
Source
Related Link
Share with