Multiple implementations of iSCSI Enterprise Target are prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary-checks on user-supplied data.
An attacker may exploit this issue to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will result in a denial-of-service condition.
The following products are affected:
iSCSI Enterprise Target 1.4.20.1 and prior
Generic SCSI Target Subsystem for Linux 1.0.1.1 and prior
Linux SCSI target framework 1.0 and prior