VDB
CVE-2007-3100
CVE-2007-3100
PUBLISHED
CVSS 2.0999999046325684 LOW
usr/log.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 uses a semaphore with insecure permissions (world-writable/world-readable) for managing log messages using shared memory, which allows local users to cause a denial of service (hang) by grabbing the semaphore.
EPSS 0.05% · 17.5th percentile
Risk Scores
CVSS 2.0
2.0999999046325684
EPSS Score
0.05%
17.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | open_iscsi | 0 |
| n/a | n/a | n/a |
Timeline
- Jun 14, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=243719 url
- 25679 third-party-advisory
- 37270 vdb
- 24471 vdb
- openiscsi-log-dos(34943) vdb
- 1018246 vdb
- http://support.novell.com/techcenter/psdb/187174044e1dbe78726bcf840f7530ed.html url
- 26438 third-party-advisory
- SUSE-SR:2007:017 vendor-advisory
- 26543 third-party-advisory
- 25749 third-party-advisory
- http://svn.berlios.de/viewcvs/open-iscsi?rev=858&view=rev url
- oval:org.mitre.oval:def:10653 vdb
- DSA-1314 vendor-advisory
- RHSA-2007:0497 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-3100 advisory