MDVSA-2011:196
- Package name
- ipmitool
- Date
- 2011-12-28
- Advisory ID
- MDVSA-2011:196
- Affected versions
- MES5 i586 , 2010.1 i586 , 2011 x86_64 , 2011 i586 , MES5 x86_64 , 2010.1 x86_64
Problem description
A vulnerability has been discovered and corrected in ipmitool:
ipmievd as used in the ipmitool package uses 0666 permissions for
its ipmievd.pid PID file, which allows local users to kill arbitrary
processes by writing to this file (CVE-2011-4339).
In Mandriva the ipmievd daemon from the ipmitool package does not
have an initscript to start and stop the service, however one could
rather easily craft an initscript or start the service by other means
rendering the system vulnerable to this issue.
The updated packages have been patched to correct this issue.
Updated packages
MES5 i586
9be0e6f208f23d65f2fa1a2691244408 mes5/i586/ipmitool-1.8.9-4.1mdvmes5.2.i586.rpm 1e97cbfb4abfff4c7020cdef74af3f35 mes5/SRPMS/ipmitool-1.8.9-4.1mdvmes5.2.src.rpm
2010.1 i586
f6c2f49d841734613a86ee619e423042 2010.1/i586/ipmitool-1.8.11-8.1mdv2010.2.i586.rpm 14a2b444b863a7c1e5fcf691be9173bf 2010.1/SRPMS/ipmitool-1.8.11-8.1mdv2010.2.src.rpm
2011 x86_64
3239950450cb9cf73fba6e12d24f6e37 2011/x86_64/ipmitool-1.8.11-8.1-mdv2011.0.x86_64.rpm e17dfb205619911e04d6c16021f17855 2011/SRPMS/ipmitool-1.8.11-8.1.src.rpm
2011 i586
523c03fd637f420e6f5e3e64abc433e1 2011/i586/ipmitool-1.8.11-8.1-mdv2011.0.i586.rpm e17dfb205619911e04d6c16021f17855 2011/SRPMS/ipmitool-1.8.11-8.1.src.rpm
MES5 x86_64
0e46751e107cede43b047cda09c17b80 mes5/x86_64/ipmitool-1.8.9-4.1mdvmes5.2.x86_64.rpm 1e97cbfb4abfff4c7020cdef74af3f35 mes5/SRPMS/ipmitool-1.8.9-4.1mdvmes5.2.src.rpm
2010.1 x86_64
cebb9f5f90b7751f521d660e44863ee7 2010.1/x86_64/ipmitool-1.8.11-8.1mdv2010.2.x86_64.rpm 14a2b444b863a7c1e5fcf691be9173bf 2010.1/SRPMS/ipmitool-1.8.11-8.1mdv2010.2.src.rpm
