ipmitool-1.8.15-3.AXS4

エラータID: AXSA:2020-4690:02

Release date: 
Monday, April 6, 2020 - 20:44
Subject: 
ipmitool-1.8.15-3.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

The ipmitool packages contain a command-line utility for interfacing with devices that support the Intelligent Platform Management Interface (IPMI) specification. IPMI is an open standard for machine health, inventory, and remote power control.

Security Fix(es):

* ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c (CVE-2020-5208)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2020-5208
It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. ipmitool-1.8.15-3.AXS4.src.rpm
    MD5: 2d546597160ce12b684f07b209e72ac1
    SHA-256: d4a89634b83742c500f1843734fbf71caba5a9ae1bf61cc3c8d8791d7ac6cb1f
    Size: 756.90 kB

Asianux Server 4 for x86
  1. ipmitool-1.8.15-3.AXS4.i686.rpm
    MD5: c4a1757111ae44652908d789f29db809
    SHA-256: 0fb61cbae30a004049dc70f8454a33d7787c277be16a4bf4f6a9edc79e50526d
    Size: 460.90 kB

Asianux Server 4 for x86_64
  1. ipmitool-1.8.15-3.AXS4.x86_64.rpm
    MD5: c35be15aac5c47dd011252119ef985c7
    SHA-256: c20a0f883cedc30e2ab11d247bc5b04dff097d0d98d8431cd789ffc2ccc35bf5
    Size: 464.41 kB