Oval Definition:oval:com.redhat.rhsa:def:20100518
Revision Date:2010-07-08Version:637
Title:RHSA-2010:0518: scsi-target-utils security update (Important)
Description:The scsi-target-utils package contains the daemon and tools to set up and monitor SCSI targets. Currently, iSCSI software and iSER targets are supported.

  • Multiple buffer overflow flaws were found in scsi-target-utils' tgtd daemon. A remote attacker could trigger these flaws by sending a carefully-crafted Internet Storage Name Service (iSNS) request, causing the tgtd daemon to crash. (CVE-2010-2221)

    Red Hat would like to thank the Vulnerability Research Team at TELUS Security Labs and Fujita Tomonori for responsibly reporting these flaws.

    All scsi-target-utils users should upgrade to this updated package, which contains a backported patch to correct these issues. All running scsi-target-utils services must be restarted for the update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-2221
    RHSA-2010:0518
    RHSA-2010:0518-01
    RHSA-2010:0518-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND scsi-target-utils is earlier than 0:0.0-6.20091205snap.el5_5.3
  • AND scsi-target-utils is signed with Red Hat redhatrelease2 key
  • BACK