VDB
CVE-2007-3099
CVE-2007-3099
PUBLISHED
CVSS 2.0999999046325684 LOW
usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 checks the client's UID on the listening AF_LOCAL socket instead of the new connection, which allows remote attackers to access the management interface and cause a denial of service (iscsid exit or iSCSI connection loss).
EPSS 0.23% · 46.3th percentile
Risk Scores
CVSS 2.0
2.0999999046325684
EPSS Score
0.23%
46.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | enterprise_linux | 5.0, 5.0 |
| n/a | n/a | n/a |
Timeline
- Jun 14, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=243719 url
- 25679 third-party-advisory
- 24471 vdb
- oval:org.mitre.oval:def:11595 vdb
- 1018246 vdb
- 37269 vdb
- http://support.novell.com/techcenter/psdb/187174044e1dbe78726bcf840f7530ed.html url
- 26438 third-party-advisory
- SUSE-SR:2007:017 vendor-advisory
- 26543 third-party-advisory
- 25749 third-party-advisory
- http://svn.berlios.de/viewcvs/open-iscsi?rev=857&view=rev url
- DSA-1314 vendor-advisory
- openiscsi-mgmtipc-dos(34944) vdb
- RHSA-2007:0497 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-3099 advisory