Saturday, December 31, 2011

[SECURITY] [DSA 2376-2] ipmitool security update

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-2376-2 security@debian.org
http://www.debian.org/security/ Thijs Kinkhorst
December 31, 2011 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : ipmitool
Vulnerability : insecure pid file
Problem type : local
Debian-specific: no
CVE ID : CVE-2011-4339
Debian Bug : 651917

It was discovered that OpenIPMI, the Intelligent Platform Management
Interface library and tools, used too wide permissions PID file,
which allows local users to kill arbitrary processes by writing to
this file.

The original announcement didn't contain corrections for the Debian
5.0 "lenny" distribution. This update adds packages for lenny.

For the oldstable distribution (lenny), this problem has been fixed in
version 1.8.9-2+squeeze1. (Although the version number contains the
string "squeeze", this is in fact an update for lenny.)

For the stable distribution (squeeze), this problem has been fixed in
version 1.8.11-2+squeeze2.

For the unstable distribution (sid), this problem has been fixed in
version 1.8.11-5.

We recommend that you upgrade your ipmitool packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQEcBAEBAgAGBQJO/v4FAAoJEOxfUAG2iX57ZxIH/3VOGKFEqkiYJyAeB96EA9d1
QKwRWxJmc+gsCB4cruNUWihCZpvgUVYHY7sRUqC+z5q5CidCehT6MRc+aBtbq0CI
mroBMkTfMl135wYXtEabThDx/gHY+gKgzkqnalPEDAAsY6hMi3YGHeB7VXFClH/c
mManIlimI9qbvBM/FvLCx0e43oBzNgdgbyhZpZO22CugMXwGQjZNfvAE+hfW2n25
fScxAtJTKcg9Wp2buuE7HYvn0dh9m/y8uw/mFwIYr7DLvwWRAcA+NdvCY4o863KT
0eJuPtK685CLFRwKGBKzuBflUBtb7fTpg2hW4GhhHQUF0aHz6Vz0Cpgf715I/bA=
=xZPT
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: http://lists.debian.org/20111231122117.DCE4559DF0@kinkhorst.com

3 comments:

  1. Anonymous4:06 AM

    Howdy, i read your blog occasionally and i own a similar one and i was just
    curious if you get a lot of spam remarks? If so how do you stop it, any plugin or anything you can suggest?
    I get so much lately it's driving me insane so any assistance is very much appreciated.

    My web blog ... forgot my password

    ReplyDelete
  2. Anonymous3:02 PM

    Not all hobbies cost money but every hobby does require time and in the business sense,
    time is money. Green, who had taken his case to the
    appeals court after losing in a lower-court ruling,
    had argued that his family would have to either "violate their faith by covering abortion-causing drugs or be exposed to severe penalties. If you are horrible on keeping with is better than or time, this is the totally obvious suggestion for training.

    Take a look at my blog post - psychic readings

    ReplyDelete
  3. Anonymous12:41 AM

    An impressive share! I have just forwarded this onto a co-worker who has been conducting a little homework on this.
    And he in fact bought me dinner simply because I stumbled upon it for him.
    .. lol. So allow me to reword this.... Thank YOU
    for the meal!! But yeah, thanx for spending the time to talk about this matter here on your site.


    Also visit my web blog :: password hack

    ReplyDelete