Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-28374
Description:In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2021.0093.1   1.3.6.1.4.1.25623.1.1.10.2021.0047   1.3.6.1.4.1.25623.1.0.892557   1.3.6.1.4.1.25623.1.0.878819   1.3.6.1.4.1.25623.1.0.844825   1.3.6.1.4.1.25623.1.0.892586   1.3.6.1.4.1.25623.1.0.878818   1.3.6.1.4.1.25623.1.0.844786   1.3.6.1.4.1.25623.1.0.878880   1.3.6.1.4.1.25623.1.0.878816   1.3.6.1.4.1.25623.1.0.878822   1.3.6.1.4.1.25623.1.0.844846   1.3.6.1.4.1.25623.1.0.844808   1.3.6.1.4.1.25623.1.0.704843  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-28374
Debian Security Information: DSA-4843 (Google Search)
https://www.debian.org/security/2021/dsa-4843
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LTGQDYIEO2GOCOOKADBHEITF44GY55QF/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HK7SRTITN5ABAUOOIGFVR7XE5YKYYAVO/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FZEUPID5DZYLZBIO4BEVLHFUDZZIFL57/
http://packetstormsecurity.com/files/161229/Kernel-Live-Patch-Security-Notice-LSN-0074-1.html
https://bugzilla.suse.com/attachment.cgi?id=844938
https://bugzilla.suse.com/show_bug.cgi?id=1178372
https://lists.debian.org/debian-lts-announce/2021/02/msg00018.html
https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html
http://www.openwall.com/lists/oss-security/2021/01/13/2
http://www.openwall.com/lists/oss-security/2021/01/13/5




© 1998-2025 E-Soft Inc. All rights reserved.