![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2021-3139 |
Description: | In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport- layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.844804 1.3.6.1.4.1.25623.1.0.853689 1.3.6.1.4.1.25623.1.0.853642 1.3.6.1.4.1.25623.1.1.4.2021.0158.1 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2021-3139 https://bugzilla.suse.com/attachment.cgi?id=844938 https://bugzilla.suse.com/show_bug.cgi?id=1178372 https://www.openwall.com/lists/oss-security/2021/01/12/12 http://www.openwall.com/lists/oss-security/2021/01/13/5 |