An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackersĀ to create root-owned files outside the database and inject lines into the record. This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
{
"binaries": [
{
"binary_name": "iscsiuio",
"binary_version": "2.1.5-1ubuntu1.1"
},
{
"binary_name": "libopeniscsiusr",
"binary_version": "2.1.5-1ubuntu1.1"
},
{
"binary_name": "libopeniscsiusr0.2.0",
"binary_version": "2.1.5-1ubuntu1.1"
},
{
"binary_name": "open-iscsi",
"binary_version": "2.1.5-1ubuntu1.1"
}
]
}