Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
iscsi_discovery in open-iscsi could be made to overwrite files as the
administrator.
Software Description:
- open-iscsi: Open Source iSCSI implementation
Details:
Colin Watson discovered that iscsi_discovery in Open-iSCSI did not safely
create temporary files. A local attacker could exploit this to to overwrite
arbitrary files with root privileges.
The problem can be corrected by updating your system to the following package versions: Ubuntu 8.04 LTS: open-iscsi 2.0.865-1ubuntu3.5 In general, a standard system update will make all the necessary changes.
CVE-2009-1297
Get the latest Linux and open source security news straight to your inbox.