CVE-2020-5208

It’s been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19.

Summary:

It’s been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19.

Reference Links(if available):

  • https://github.com/ipmitool/ipmitool/security/advisories/GHSA-g659-9qxw-p7cp
  • https://github.com/ipmitool/ipmitool/commit/e824c23316ae50beb7f7488f2055ac65e8b341f2
  • https://lists.debian.org/debian-lts-announce/2020/02/msg00006.html
  • https://lists.fedoraproject.org/archives/list/[email protected]/message/RYYEKUAUTCWICM77HOEGZDVVEUJLP4BP/
  • https://lists.fedoraproject.org/archives/list/[email protected]/message/K2BPW66KDP4H36AGZXLED57A3O2Y6EQW/
  • CVSS Score (if available)

    v2: / MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P

    v3: / HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

    Links to Exploits(if available)