2.1
CVSSv2

CVE-2007-3100

Published: 14/06/2007 Updated: 11/10/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

usr/log.c in iscsid in open-iscsi (iscsi-initiator-utils) prior to 2.0-865 uses a semaphore with insecure permissions (world-writable/world-readable) for managing log messages using shared memory, which allows local users to cause a denial of service (hang) by grabbing the semaphore.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat open_iscsi

Vendor Advisories

Debian Bug report logs - #429225 [CVE-2007-3099, CVE-2007-3100] local DoS vulnerabilities Package: open-iscsi; Maintainer for open-iscsi is Debian iSCSI Maintainers <open-iscsi@packagesdebianorg>; Source for open-iscsi is src:open-iscsi (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Sat, ...
Several local and remote vulnerabilities have been discovered in open-iscsi, a transport-independent iSCSI implementation The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-3099 Olaf Kirch discovered that due to a programming error access to the management interface socket was insufficiently prote ...