USN-4871-1
Dashboard / Vulnerabilities / USN-4871-1
USN-4871-1
Summary: targetcli-fb vulnerabilities
Details: It was discovered that targetcli-fb did not properly manage socket permissions. A local attacker could use this issue to modify the iSCSI configuration resulting in a denial of service, obtain sensitive information or execute arbitrary code. (CVE-2020-10699) It was discovered that targetcli-fb did not properly manage permissions for /etc/target and underneath backup directory/files. An attacker could use this issue to access sensitive information. (CVE-2020-13867)
References: https://ubuntu.com/security/notices/USN-4871-1, https://ubuntu.com/security/CVE-2020-10699, https://ubuntu.com/security/CVE-2020-13867
Affected packages
Package
Name: targetcli-fb
Purl: pkg:deb/ubuntu/targetcli-fb@1:2.1.51-0ubuntu1+esm1?arch=source&distro=esm-apps/focal
Affected ranges
Type: ECOSYSTEM
Events:
