Logo
componentipmitool
Name
ipmitool
Version
1.8.18
Type
library
Description
Utility for IPMI control
Licenses
BSD-3-Clause
PURL
-
CPE
cpe:2.3:*:ipmitool_project:ipmitool:1.8.18:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
1.8.19
scarthgap
1.8.19

Patches#


#
Title
Author
Resolve
1
fru: Fix buffer overflow vulnerabilities
Chrostoper Ertl <chertl@microsoft.com>
CVE-2020-5208
2
lanp: Fix buffer overflows in get_lan_param_select
Chrostoper Ertl <chertl@microsoft.com>
CVE-2020-5208
3
Migrate to openssl 1.1
Khem Raj <raj.khem@gmail.com>
4
channel: Fix buffer overflow
Chrostoper Ertl <chertl@microsoft.com>
CVE-2020-5208
5
session: Fix buffer overflow in ipmi_get_session_info
Chrostoper Ertl <chertl@microsoft.com>
CVE-2020-5208
6
fru, sdr: Fix id_string buffer overflows
Chrostoper Ertl <chertl@microsoft.com>
CVE-2020-5208
7
hpmfwupg: move variable definition to .c file
Vaclav Dolezal <vdolezal@redhat.com>
8
fru: Fix buffer overflow in ipmi_spd_print_fru
Chrostoper Ertl <chertl@microsoft.com>
CVE-2020-5208

Vulnerabilities#


Name
Analysis
Description
Patched
It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19.