2.1
CVE-2007-3100
- EPSS 0.05%
- Veröffentlicht 14.06.2007 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
usr/log.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 uses a semaphore with insecure permissions (world-writable/world-readable) for managing log messages using shared memory, which allows local users to cause a denial of service (hang) by grabbing the semaphore.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Open Iscsi Version <= 2.0-864
Redhat ≫ Enterprise Linux Version5.0 Editiondesktop
Redhat ≫ Enterprise Linux Version5.0 Editionserver
Redhat ≫ Enterprise Linux Version5.0 Editionserver
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.135 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:N/I:N/A:P
|