2.1
CVSSv2

CVE-2007-3099

Published: 14/06/2007 Updated: 11/10/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) prior to 2.0-865 checks the client's UID on the listening AF_LOCAL socket instead of the new connection, which allows remote malicious users to access the management interface and cause a denial of service (iscsid exit or iSCSI connection loss).

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux 5.0

Vendor Advisories

Debian Bug report logs - #429225 [CVE-2007-3099, CVE-2007-3100] local DoS vulnerabilities Package: open-iscsi; Maintainer for open-iscsi is Debian iSCSI Maintainers <open-iscsi@packagesdebianorg>; Source for open-iscsi is src:open-iscsi (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Sat, ...
Several local and remote vulnerabilities have been discovered in open-iscsi, a transport-independent iSCSI implementation The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-3099 Olaf Kirch discovered that due to a programming error access to the management interface socket was insufficiently prote ...