Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 11.04/10.10: USN-1156-1 Critical: tgt DoS Threat

ubuntu
Calendar Grey June 21, 2011
Scroller Ubuntu
Mitigating tgt weaknesses in Ubuntu 11.04 and 10.10 through essential patches for heightened protection.
An attacker could send crafted input to tgt and cause it to crash or run arbitrary programs.

Summary

An attacker could send crafted input to tgt and cause it to crash or run

arbitrary programs.

Software Description:

- tgt: Linux SCSI target user-space tools

Details:

It was discovered that tgt incorrectly handled long iSCSI name strings, and

invalid PDUs. A remote attacker could exploit this to cause tgt to crash,

resulting in a denial of service, or possibly execute arbitrary code. This

issue only affected Ubuntu 10.10. (CVE-2010-2221)

Emmanuel Bouillon discovered that tgt incorrectly handled certain iSCSI

logins. A remote attacker could exploit this to cause tgt to crash,

resulting in a denial of service, or possibly execute arbitrary code.

(CVE-2011-0001)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  tgt                             1:1.0.13-0ubuntu2.1

Ubuntu 10.10:
  tgt                             1:1.0.4-1ubuntu4.1

In general, a standard system update will make all the necessary changes.

References

CVE-2010-2221, CVE-2011-0001

Severity
critical
Lowest
Low
Medium
High
Critical

June 21, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.