Описание
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
A flaw was found in FreeIPMI. A stack-based buffer overflow in the ipmi-oem utility can lead to arbitrary code execution. This vulnerability can be exploited by a local user who executes a specially crafted ipmi-oem command, potentially when processing untrusted data from a remote source.
Отчет
A stack-based buffer overflow vulnerability in the ipmi-oem utility of FreeIPMI could allow a local attacker to execute arbitrary code. To exploit this moderate-severity flaw, a local user must be tricked into running a specially crafted command that processes untrusted data. The requirement for local access and active user interaction significantly increases the overall complexity of the attack.
Меры по смягчению последствий
To mitigate this vulnerability, implement robust boundary checks before copying data to ensure the input size does not exceed the allocated stack buffer capacity. Developers should replace unsafe, unbounded memory functions (like strcpy or sprintf) with safe, length-restricted alternatives (such as strncpy or snprintf). Furthermore, deploying the application in environments that enforce compiler-based protections like stack canaries and Address Space Layout Randomization (ASLR) will prevent successful code execution
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freeipmi | Affected | ||
| Red Hat Enterprise Linux 6 | freeipmi | Not affected | ||
| Red Hat Enterprise Linux 7 | freeipmi | Not affected | ||
| Red Hat Enterprise Linux 8 | freeipmi | Affected | ||
| Red Hat Enterprise Linux 9 | freeipmi | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow i ...
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
EPSS
7.5 High
CVSS3