On 02/04/2020 01:04, Alex Murray wrote: > Upstream have merged in a fix for the world-writable targetcli-fb daemon > socket - https://github.com/open-iscsi/targetcli-fb/issues/162 - and > assigned CVE-2020-10699 for it - but there has been no official release. > With this fix in place, I would be happy to change the NACK to an ACK > for targetcli-fb. > > ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-10699
Alex, I left the targetcli-fb MIR attempt to be handled at 20.10. I'll continue this shortly and will handle this. Thanks for the highlight.
On 02/04/2020 01:04, Alex Murray wrote: /github. com/open- iscsi/targetcli -fb/issues/ 162 - and /cve.mitre. org/cgi- bin/cvename. cgi?name= 2020-10699
> Upstream have merged in a fix for the world-writable targetcli-fb daemon
> socket - https:/
> assigned CVE-2020-10699 for it - but there has been no official release.
> With this fix in place, I would be happy to change the NACK to an ACK
> for targetcli-fb.
>
> ** CVE added: https:/
Alex, I left the targetcli-fb MIR attempt to be handled at 20.10. I'll
continue this shortly and will handle this. Thanks for the highlight.