It was discovered that tgt incorrectly tried to achieve entropy by calling rand without srand. An attacker could possibly use this issue to make tgt generate an identical sequence of challenges, resulting in authentication bypass.
{
"binaries": [
{
"binary_version": "1:1.0.43-0ubuntu4.1~14.04.3+esm1",
"binary_name": "tgt"
}
],
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8325-1.json"
{
"ecosystem": "Ubuntu:Pro:14.04:LTS",
"cves": [
{
"id": "CVE-2024-45751",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
]
}
{
"binaries": [
{
"binary_name": "tgt",
"binary_version": "1:1.0.63-1ubuntu1.1+esm1"
},
{
"binary_version": "1:1.0.63-1ubuntu1.1+esm1",
"binary_name": "tgt-rbd"
}
],
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8325-1.json"
{
"ecosystem": "Ubuntu:Pro:16.04:LTS",
"cves": [
{
"id": "CVE-2024-45751",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
]
}
{
"binaries": [
{
"binary_name": "tgt",
"binary_version": "1:1.0.72-1ubuntu1+esm1"
},
{
"binary_name": "tgt-rbd",
"binary_version": "1:1.0.72-1ubuntu1+esm1"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8325-1.json"
{
"ecosystem": "Ubuntu:Pro:18.04:LTS",
"cves": [
{
"id": "CVE-2024-45751",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
]
}
{
"binaries": [
{
"binary_name": "tgt",
"binary_version": "1:1.0.80-1ubuntu2+esm1"
},
{
"binary_version": "1:1.0.80-1ubuntu2+esm1",
"binary_name": "tgt-glusterfs"
},
{
"binary_version": "1:1.0.80-1ubuntu2+esm1",
"binary_name": "tgt-rbd"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8325-1.json"
{
"ecosystem": "Ubuntu:Pro:22.04:LTS",
"cves": [
{
"id": "CVE-2024-45751",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
]
}
{
"binaries": [
{
"binary_version": "1:1.0.85-1.1ubuntu6+esm1",
"binary_name": "tgt"
},
{
"binary_name": "tgt-glusterfs",
"binary_version": "1:1.0.85-1.1ubuntu6+esm1"
},
{
"binary_version": "1:1.0.85-1.1ubuntu6+esm1",
"binary_name": "tgt-rbd"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8325-1.json"
{
"ecosystem": "Ubuntu:Pro:24.04:LTS",
"cves": [
{
"id": "CVE-2024-45751",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
]
}