Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-42934

Опубликовано: 22 авг. 2024
Источник: redhat
CVSS3: 5

Описание

OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) authentication bypass or code execution.

A flaw was found in the IPMI simulator (ipmi_sim) component of OpenIPMI. Due to a missing check in the authorization type on incoming LAN messages, an attacker may be able to trigger a denial of service.

Отчет

There is a low risk of this flaw being used to authenticate messages without actual authentication. This issue affects systems where ipmi_sim has been deployed in production. The main OpenIPMI library is not affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10OpenIPMINot affected
Red Hat Enterprise Linux 6OpenIPMIOut of support scope
Red Hat Enterprise Linux 7OpenIPMIOut of support scope
Red Hat Enterprise Linux 8OpenIPMIWill not fix
Red Hat Enterprise Linux 9OpenIPMIFixedRHSA-2024:803714.10.2024
Red Hat Enterprise Linux 9.2 Extended Update SupportOpenIPMIFixedRHSA-2024:808114.10.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2308375openipmi: missing check on the authorization type on incoming LAN messages in IPMI simulator

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
8 месяцев назад

OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) authentication bypass or code execution.

CVSS3: 5
nvd
8 месяцев назад

OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) authentication bypass or code execution.

CVSS3: 5
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 5
debian
8 месяцев назад

OpenIPMI before 2.0.36 has an out-of-bounds array access (for authenti ...

suse-cvrf
8 месяцев назад

Security update for OpenIPMI

5 Medium

CVSS3