Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Ubuntu 8.04 LTS USN-1235-1 Critical: Open-iSCSI File Overwrite Exploit

ubuntu
Calendar Grey October 20, 2011
Scroller Ubuntu
The recent Open-iSCSI flaw discovered in Ubuntu poses a serious risk, enabling file overwrites with administrative privileges. Immediate updates are essential to safeguard system integrity.
iscsi_discovery in open-iscsi could be made to overwrite files as the administrator.

Summary

iscsi_discovery in open-iscsi could be made to overwrite files as the

administrator.

Software Description:

- open-iscsi: Open Source iSCSI implementation

Details:

Colin Watson discovered that iscsi_discovery in Open-iSCSI did not safely

create temporary files. A local attacker could exploit this to to overwrite

arbitrary files with root privileges.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 8.04 LTS:
  open-iscsi                      2.0.865-1ubuntu3.5

In general, a standard system update will make all the necessary changes.

References

CVE-2009-1297

Severity
critical
Lowest
Low
Medium
High
Critical

October 20, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.