5

CVE-2011-0001

Double free vulnerability in the iscsi_rx_handler function (usr/iscsi/iscsid.c) in the tgt daemon (tgtd) in Linux SCSI target framework (tgt) before 1.0.14, aka scsi-target-utils, allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown vectors related to a buffer overflow during iscsi login.  NOTE: some of these details are obtained from third party information.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZaalTgt Version <= 1.0.13
ZaalTgt Version0.9.5
ZaalTgt Version1.0.0
ZaalTgt Version1.0.1
ZaalTgt Version1.0.2
ZaalTgt Version1.0.3
ZaalTgt Version1.0.4
ZaalTgt Version1.0.5
ZaalTgt Version1.0.6
ZaalTgt Version1.0.7
ZaalTgt Version1.0.8
ZaalTgt Version1.0.9
ZaalTgt Version1.0.10
ZaalTgt Version1.0.11
ZaalTgt Version1.0.12
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.34% 0.925
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P