Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 22 articles for you...
203

Mageia 8 MGASA-2023-0135 Critical: Ipmitool Buffer Overflow Threat

It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19. (CVE-2020-5208) . MGASA-2023-0135 - Updated ipmitool packages fix security vulnerability Publication date: 11 Apr 2023 URL: https://advisories.mageia.org/MGASA-2023-0135.html Type: security Affected Mageia releases: 8 CVE: CVE-2020-5208 It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19. (CVE-2020-5208) References: - https://bugs.mageia.org/show_bug.cgi?id=31759 - https://ubuntu.com/security/notices/USN-5997-1 - https://www.cve.org/CVERecord?id=CVE-2020-5208 SRPMS: - 8/core/ipmitool-1.8.18-7.1.mga8 . An important security patch for ipmitool in Mageia, issued on April 11, 2023, resolves a critical buffer overflow vulnerability.. Mageia Ipmitool Security Update, Buffer Overflow, Remote Code Execution, Critical Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 11, 2023 Critical Mageia
172

Ubuntu 20.04 LTS USN-5997-1 Moderate: IPMItool Crash Risk

IPMItool could be made to crash or run programs if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-5997-1 April 04, 2023 ipmitool vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM Summary: IPMItool could be made to crash or run programs if it received specially crafted input. Software Description: - ipmitool: utility for IPMI control with kernel driver or LAN interface (dae Details: It was discovered that IPMItool was not properly checking the data received from a remote LAN party. A remote attacker could possibly use this issue to to cause a crash or arbitrary code execution. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: ipmitool 1.8.18-8ubuntu0.1 Ubuntu 18.04 LTS: ipmitool 1.8.18-5ubuntu0.2 Ubuntu 16.04 ESM: ipmitool 1.8.16-3ubuntu0.2+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5997-1 CVE-2020-5208 Package Information: https://launchpad.net/ubuntu/+source/ipmitool/1.8.18-8ubuntu0.1 https://launchpad.net/ubuntu/+source/ipmitool/1.8.18-5ubuntu0.2 . Due to major security flaws found in IPMItool on various Ubuntu versions, users must act quickly. Follow recommended steps to secure your systems.. ipmitool security, Ubuntu update, code execution risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 04, 2023 Important Ubuntu
197

Debian LTS: DLA-2699-1 Moderate: Ipmitool Buffer Overflow

An issue has been found in ipmitool, an utility for IPMI control with kernel driver or LAN interface. Neglecting proper checking of input data might result in buffer overflows . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2699-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz July 01, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ipmitool Version : 1.8.18-3+deb9u1 CVE ID : CVE-2020-5208 An issue has been found in ipmitool, an utility for IPMI control with kernel driver or LAN interface. Neglecting proper checking of input data might result in buffer overflows and possible remote code execution. For Debian 9 stretch, this problem has been fixed in version 1.8.18-3+deb9u1. We recommend that you upgrade your ipmitool packages. For the detailed security status of ipmitool please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ipmitool Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian LTS Announcement DLA-2699-1 highlights a critical vulnerability in ipmitool that poses a buffer overflow threat, potentially allowing unauthorized remote code execution.. ipmitool update, debian security, buffer overflow risk, remote code execution. . LinuxSecurity.com Team

Calendar%202 Jun 30, 2021 Debian LTS
198

Arch Linux: ASA-202102-39 High: ipmitool Arbitrary Code Execution

The package ipmitool before version 1.8.18-7 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-202102-39 ========================================= Severity: High Date : 2021-02-27 CVE-ID : CVE-2020-5208 Package : ipmitool Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-1596 Summary ====== The package ipmitool before version 1.8.18-7 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 1.8.18-7. # pacman -Syu "ipmitool> =1.8.18-7" The problem has been fixed upstream but no release is available yet. Workaround ========= None. Description ========== It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19. Impact ===== A remote server could execute arbitrary code on the client. References ========= https://bugs.archlinux.org/task/69708 https://github.com/ipmitool/ipmitool/security/advisories/GHSA-g659-9qxw-p7cp https://github.com/ipmitool/ipmitool/commit/e824c23316ae50beb7f7488f2055ac65e8b341f2 https://github.com/ipmitool/ipmitool/commit/840fb1cbb4fb365cb9797300e3374d4faefcdb10 https://github.com/ipmitool/ipmitool/commit/41d7026946fafbd4d1ec0bcaca3ea30a6e8eed22 https://github.com/ipmitool/ipmitool/commit/9452be87181a6e83cfcc768b3ed8321763db50e4 https://github.com/ipmitool/ipmitool/commit/d45572d71e70840e0d4c50bf48218492b79c1a10 https://github.com/ipmitool/ipmitool/commit/7ccea283dd62a05a320c1921e3d8d71a87772637 https://security.archlinux.org/CVE-2020-5208 . Arch Linux Security Advisory ASA-202102-39 ========================================= Severity: High . package, ipmitool, version, vulnerable, arbitrary, execution, linux. . LinuxSecurity.com Team

Calendar%202 Mar 01, 2021 ArchLinux
91

Gentoo: 202201-05 Critical: Libcurl Buffer Overflow Vulnerability

A buffer overflow in ipmitool might allow remote attacker(s) to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202101-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: ipmitool: Multiple vulnerabilities Date: January 10, 2021 Bugs: #708436 ID: 202101-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow in ipmitool might allow remote attacker(s) to execute arbitrary code. Background ========= Utility for controlling IPMI enabled devices. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/ipmitool < 1.8.18_p20201004-r1> = 1.8.18_p20201004-r1 Description ========== Multiple vulnerabilities have been discovered in ipmiool. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All ipmitool users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =sys-apps/ipmitool-1.8.18_p20201004-r1" References ========= [ 1 ] CVE-2020-5208 https://nvd.nist.gov/vuln/detail/CVE-2020-5208 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202101-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and securityof our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Vulnerabilities in ipmitool are outlined in Gentoo's advisory, highlighting risks like unauthorized remote code execution and denial of service attacks.. Gentoo Advisory, ipmitool Exploit, Remote Code Risks, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 10, 2021 Critical Gentoo
98

Critical Security Update RHSA-2020-2286-01 for ipmitool Buffer Overflow

An update for ipmitool is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: ipmitool security update Advisory ID: RHSA-2020:2286-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2286 Issue date: 2020-05-26 CVE Names: CVE-2020-5208 ==================================================================== 1. Summary: An update for ipmitool is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6) - x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6) - noarch Red Hat Enterprise Linux Server EUS (v. 7.6) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.6) - noarch Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, ppc64le, s390x Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - noarch 3. Description: The ipmitool packages contain a command-line utility for interfacing with devices that support the Intelligent Platform Management Interface (IPMI) specification. IPMI is an open standard for machine health, inventory, and remote power control. Security Fix(es): * ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c (CVE-2020-5208) For more details about the securityissue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, the IPMI event daemon (ipmievd) will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1798721 - CVE-2020-5208 ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6): Source: ipmitool-1.8.18-9.el7_6.src.rpm x86_64: ipmitool-1.8.18-9.el7_6.x86_64.rpm ipmitool-debuginfo-1.8.18-9.el7_6.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6): noarch: bmc-snmp-proxy-1.8.18-9.el7_6.noarch.rpm exchange-bmc-os-info-1.8.18-9.el7_6.noarch.rpm Red Hat Enterprise Linux Server EUS (v. 7.6): Source: ipmitool-1.8.18-9.el7_6.src.rpm ppc64: ipmitool-1.8.18-9.el7_6.ppc64.rpm ipmitool-debuginfo-1.8.18-9.el7_6.ppc64.rpm ppc64le: ipmitool-1.8.18-9.el7_6.ppc64le.rpm ipmitool-debuginfo-1.8.18-9.el7_6.ppc64le.rpm s390x: ipmitool-1.8.18-9.el7_6.s390x.rpm ipmitool-debuginfo-1.8.18-9.el7_6.s390x.rpm x86_64: ipmitool-1.8.18-9.el7_6.x86_64.rpm ipmitool-debuginfo-1.8.18-9.el7_6.x86_64.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7): Source: ipmitool-1.8.18-9.el7_6.src.rpm aarch64: ipmitool-1.8.18-9.el7_6.aarch64.rpm ipmitool-debuginfo-1.8.18-9.el7_6.aarch64.rpm ppc64le: ipmitool-1.8.18-9.el7_6.ppc64le.rpm ipmitool-debuginfo-1.8.18-9.el7_6.ppc64le.rpm s390x: ipmitool-1.8.18-9.el7_6.s390x.rpm ipmitool-debuginfo-1.8.18-9.el7_6.s390x.rpm Red Hat Enterprise Linux Server Optional EUS (v. 7.6): noarch: bmc-snmp-proxy-1.8.18-9.el7_6.noarch.rpm exchange-bmc-os-info-1.8.18-9.el7_6.noarch.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v.7): noarch: bmc-snmp-proxy-1.8.18-9.el7_6.noarch.rpm exchange-bmc-os-info-1.8.18-9.el7_6.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-5208 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXsz7M9zjgjWX9erEAQiJcA//WSIvDp5yq6klfuWJolxHvprApAQjExlO kk+2OVtKdTGb0OEsVTnZppUDOhvI7sMiRZoJ86i9qXmtylRCfzI22noOFOZjKPLE sLZ1hCklgJGVZXRBzsJMiCo8xJM8g59q7qBXiinAyGPyQ+RzvUYK910cAkv0uAG1 S0PTbpyG/YlHiSbNkUofDt+WrIprztKnegvTgY3ktN37pr48DfGHgCGfIw1MpI5i FNhAziplkP9hNd5V6cJv1Ri9nPovunhIxqKmdVG2H7c99tN06SS58r0R5CX9juTz R6iPR8elnBCk7GoXIOyPS7BNzuBhlv3o6DOgejeAZ0ey7l9sZ4CcFPUgn+KhVbSt R7+X9MvBks/KyTgA9N+f0gKAXKVN3IfJ1hpRBGM4bAu3IHQxBAjpqX/F1km3q1NZ 9IlIsxGIMWDmF5sjRenL531YR4zVHVuqiF080aIYrK8QhiwgEcqs5f6Hib9lsGaf 2Tln9zOLJvgvQSEvn2uvK998YclenMAJoR2e1PP3UO37bSPEjqDN4qYq8eE5AVNX UnUJ4UnvTbG1TPLVteUB66LahpTeTCAyM9Qipb9+NkD6U06OUd2WfptcMsuRNclP cRcGTSmLSx8oUVYzOZLGt4WENeIiiaPKYBw4qk1yjnpUpfXnhXb2Nfa4jtZbU/3f wwY+GIIVBdg=2/K9 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical notification regarding ipmitool resolves a significant buffer overflow vulnerability for Red Hat Enterprise Linux. Implement without delay.. ipmitool Update, Red Hat Security, Buffer Overflow Fix, Linux Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 26, 2020 Important Red Hat
98

RedHat: RHSA-2020-2276-01 Important: Ipmitool Buffer Overflow Fix

An update for ipmitool is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: ipmitool security update Advisory ID: RHSA-2020:2276-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2276 Issue date: 2020-05-26 CVE Names: CVE-2020-5208 ==================================================================== 1. Summary: An update for ipmitool is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.3) - x86_64 Red Hat Enterprise Linux Server E4S (v. 7.3) - ppc64le, x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.3) - noarch Red Hat Enterprise Linux Server Optional E4S (v. 7.3) - noarch Red Hat Enterprise Linux Server Optional TUS (v. 7.3) - noarch Red Hat Enterprise Linux Server TUS (v. 7.3) - x86_64 3. Description: The ipmitool packages contain a command-line utility for interfacing with devices that support the Intelligent Platform Management Interface (IPMI) specification. IPMI is an open standard for machine health, inventory, and remote power control. Security Fix(es): * ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c (CVE-2020-5208) For more details about thesecurity issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, the IPMI event daemon (ipmievd) will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1798721 - CVE-2020-5208 ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.3): Source: ipmitool-1.8.15-8.el7_3.src.rpm x86_64: ipmitool-1.8.15-8.el7_3.x86_64.rpm ipmitool-debuginfo-1.8.15-8.el7_3.x86_64.rpm Red Hat Enterprise Linux Server E4S (v. 7.3): Source: ipmitool-1.8.15-8.el7_3.src.rpm ppc64le: ipmitool-1.8.15-8.el7_3.ppc64le.rpm ipmitool-debuginfo-1.8.15-8.el7_3.ppc64le.rpm x86_64: ipmitool-1.8.15-8.el7_3.x86_64.rpm ipmitool-debuginfo-1.8.15-8.el7_3.x86_64.rpm Red Hat Enterprise Linux Server TUS (v. 7.3): Source: ipmitool-1.8.15-8.el7_3.src.rpm x86_64: ipmitool-1.8.15-8.el7_3.x86_64.rpm ipmitool-debuginfo-1.8.15-8.el7_3.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.3): noarch: bmc-snmp-proxy-1.8.15-8.el7_3.noarch.rpm exchange-bmc-os-info-1.8.15-8.el7_3.noarch.rpm Red Hat Enterprise Linux Server Optional E4S (v. 7.3): noarch: bmc-snmp-proxy-1.8.15-8.el7_3.noarch.rpm exchange-bmc-os-info-1.8.15-8.el7_3.noarch.rpm Red Hat Enterprise Linux Server Optional TUS (v. 7.3): noarch: bmc-snmp-proxy-1.8.15-8.el7_3.noarch.rpm exchange-bmc-os-info-1.8.15-8.el7_3.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-5208 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . Morecontact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXszkLtzjgjWX9erEAQigxQ//fzB5UthRZ8UNIhLRwdql16JtsZuY53wn CI8Y/HcTzWU/Dv2u6jJrN2OU9sjJuVVsghIkZUAmp0RcqQzUJSIv4VeP+EYMbOgM rzuINZzKzq2y/E52yKzNlhQgYfySxrLw9ixhbTyV8xM+oxi/UsVu+ZvhDHU+1rEF my5zM3M6C1XvxGdE9Mr0kTQG0QzkA30h/QMaXgenS3o9NNk71+kFrXi+b7ONqJjl +ekZtCoiERS9Q4ycrNGQN53sVWu5eMFXzVve4YD+x3LXtnMXvYAf8y58g9XA7Oxc vFxqxSbbHwaoNqo9X5JpdoorAufdsVvIg4btPfoZaovONGRNsU7CrXwI3VLvB7RJ wwOjpoKENJUUa7q0qezkWoWuDvEegNb223aHOIZlceDnaWSKNTpfiKGCUUymjVgR TnQ6TSE3EqLqiAa6kex+t79AKIg6veuEPOS7uXe35vSzibrUH/xlrwAi/FKrKQmP nMk09Ve9u3AQVlKMhm97jLFKISHQ7xcDPj4Vl1R/q1JmwPl9lc/gH4Fhz3A1IWEt XdDoCjDT4yQieqq2OFXYHrVZRHtD1A1NUOU3ooAje1hT+qFRG5tPE4J4O09Z8n8Z qyZeTntg7RxEQrs3soJCybddaBIkCpVZoFBCUpeiVeZDVtFAbPyHghFCSoUo5P5x Bq6qQ+fGOm8=BleC -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical patch released for ipmitool addresses memory corruption issue in Red Hat Enterprise Linux 7.3 and similar architectures.. ipmitool Security Update, Red Hat Advisory, Linux System Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 26, 2020 Important Red Hat
98

Red Hat: RHSA-2020:2284-01 Important: Ipmitool Buffer Overflow

An update for ipmitool is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: ipmitool security update Advisory ID: RHSA-2020:2284-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2284 Issue date: 2020-05-26 CVE Names: CVE-2020-5208 ==================================================================== 1. Summary: An update for ipmitool is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.2) - x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.2) - noarch 3. Description: The ipmitool packages contain a command-line utility for interfacing with devices that support the Intelligent Platform Management Interface (IPMI) specification. IPMI is an open standard for machine health, inventory, and remote power control. Security Fix(es): * ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c (CVE-2020-5208) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update,the IPMI event daemon (ipmievd) will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1798721 - CVE-2020-5208 ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.2): Source: ipmitool-1.8.13-10.el7_2.src.rpm x86_64: ipmitool-1.8.13-10.el7_2.x86_64.rpm ipmitool-debuginfo-1.8.13-10.el7_2.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.2): noarch: bmc-snmp-proxy-1.8.13-10.el7_2.noarch.rpm exchange-bmc-os-info-1.8.13-10.el7_2.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-5208 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXszX/tzjgjWX9erEAQhe5A//btaSymd+eeG9CvEm7nEroHsiVhr1nv/6 BSLoulkF/iKlLY6F44M+0KBY6zU7uEimMIkxZP2gee4R3AMrbC3GaeyRWffEm95U 5DAeWhvDd0UeTJpRKaDCCdTrfwfptDoVEDT37X0cz2OesH7eiWd8PyvSH/RDrLRl jmryO8sz711mLQus2iJiZnTGr4mKzmrVKPxPLL0WNsEqhIBEqf5KZ+HjQLM3ljMR gFmQ0pfxmmpEqCV99BB1uzHPTy/FfYRG/nxVgsHKIdDGME/2nNQaqFLdVGFj/ngd TClnW0ADil3GAB1J8bAWB3CnNGRcmUwksvlLoKobNAvWjbsyrtHjFOHcCbncRMHd sfI8ofOCNrn4qNwVzuGD5H2Ve5ici5r2WM6INOFsYntxNmjFi0LegRQgVHQJ4Ygq 9NWSh6qj+s8ithvu5yiq6AOm9XnAD0/KJHAXIQydzRyQSM9w7207gqZYNyk2rs3H bN9YkKKywlJ0xpwezqiYV9AjuBqhPICPBMEWerlDEsC7PIb1PCjuDfewfrDycdpS n9mQhEFObigF9e1dj5T/BUniQzQ7n4bLoPBH9bQZWasr62tdOa3jflshds4leHVC 1A/DpDpBuSc08zdZXFsUTKh8tXZhNbGW++rjoaueJ8Q3371t4NYQP3Hx2rxJp0s4 UYVuLTtx5sk=QkKC -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical patch for ipmitool resolves a vulnerability related to buffer overflow in CentOS 7.2.. ipmitool Security Update, Red Hat SecurityAdvisory, Buffer Overflow Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 26, 2020 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200