Logo
vulnerabilityCVE-2020-5208
Name
CVE-2020-5208
Source
NVD ( link)Debian ( link)
Description
It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ipmitool
Patched

Vulnerability Ratings#


7.7
CVSSv31
8.8
CVSSv31
6.5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
IPMITOOL_1_8_19
Not Affected
buildroot
master
IPMITOOL_1_8_19
Not Affected
openwrt
master
1.8.19-r3
Not Affected
openwrt
openwrt-25.12
1.8.19-r3
Not Affected
yocto
master
1.8.19
Not Affected
yocto
scarthgap
1.8.19
Not Affected

Resolved with patches#


ipmitool (yocto:kirkstone)

#
Title
Author
Resolve
1
fru: Fix buffer overflow vulnerabilities
Chrostoper Ertl <chertl@microsoft.com>
CVE-2020-5208
2
lanp: Fix buffer overflows in get_lan_param_select
Chrostoper Ertl <chertl@microsoft.com>
CVE-2020-5208
3
channel: Fix buffer overflow
Chrostoper Ertl <chertl@microsoft.com>
CVE-2020-5208
4
session: Fix buffer overflow in ipmi_get_session_info
Chrostoper Ertl <chertl@microsoft.com>
CVE-2020-5208
5
fru, sdr: Fix id_string buffer overflows
Chrostoper Ertl <chertl@microsoft.com>
CVE-2020-5208
6
fru: Fix buffer overflow in ipmi_spd_print_fru
Chrostoper Ertl <chertl@microsoft.com>
CVE-2020-5208