Описание
Security update for ipmitool
This update for ipmitool fixes the following security issue:
- CVE-2020-5208: Fixed several buffer overflows (bsc#1163026).
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15 SP1
ipmitool-1.8.18-7.3.1
SUSE Linux Enterprise Module for Server Applications 15 SP1
ipmitool-bmc-snmp-proxy-1.8.18-7.3.1
Ссылки
- Link for SUSE-SU-2020:0405-1
- E-Mail link for SUSE-SU-2020:0405-1
- SUSE Security Ratings
- SUSE Bug 1163026
- SUSE CVE CVE-2020-5208 page
Описание
It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP1:ipmitool-1.8.18-7.3.1
SUSE Linux Enterprise Module for Server Applications 15 SP1:ipmitool-bmc-snmp-proxy-1.8.18-7.3.1
Ссылки
- CVE-2020-5208
- SUSE Bug 1163026