USN-4871-1: targetcli-fb vulnerabilities
15 March 2021
Several security issues were fixed in targetcli-fb.
Releases
Packages
- targetcli-fb - None
Details
It was discovered that targetcli-fb did not properly manage socket
permissions. A local attacker could use this issue to modify the iSCSI
configuration resulting in a denial of service, obtain sensitive
information or execute arbitrary code. (CVE-2020-10699)
It was discovered that targetcli-fb did not properly manage permissions for
/etc/target and underneath backup directory/files. An attacker could use
this issue to access sensitive information. (CVE-2020-13867)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
-
targetcli-fb
-
1:2.1.51-0ubuntu1+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.