Important: scsi-target-utils (SL5, SL6)

Synopsis: Important: scsi-target-utils security update
Issue Date: 2011-03-09
CVE Numbers: CVE-2011-0001

The scsi-target-utils package contains the daemon and tools to set up and
monitor SCSI targets. Currently, iSCSI software and iSER targets are
supported.

A double-free flaw was found in scsi-target-utils’ tgtd daemon. A remote
attacker could trigger this flaw by sending carefully-crafted network
traffic, causing the tgtd daemon to crash. (CVE-2011-0001)

Red Hat would like to thank Emmanuel Bouillon of NATO C3 Agency for
reporting this issue.

All scsi-target-utils users should upgrade to this updated package, which
contains a backported patch to correct this issue. All running
scsi-target-utils services must be restarted for the update to take effect.

SL5
x86_64
scsi-target-utils-1.0.8-0.el5_6.1.x86_64.rpm
i386
scsi-target-utils-1.0.8-0.el5_6.1.i386.rpm
SL6
x86_64
scsi-target-utils-1.0.4-3.el6_0.1.x86_64.rpm
i386
scsi-target-utils-1.0.4-3.el6_0.1.i686.rpm

– Scientific Linux Development Team