• [SECURITY] [DSA 2376-2] ipmitool security update

    From Thijs Kinkhorst@1:229/2 to All on Sat Dec 31 13:30:02 2011
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2376-2 [email protected] http://www.debian.org/security/ Thijs Kinkhorst December 31, 2011 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : ipmitool
    Vulnerability : insecure pid file
    Problem type : local
    Debian-specific: no
    CVE ID : CVE-2011-4339
    Debian Bug : 651917

    It was discovered that OpenIPMI, the Intelligent Platform Management
    Interface library and tools, used too wide permissions PID file,
    which allows local users to kill arbitrary processes by writing to
    this file.

    The original announcement didn't contain corrections for the Debian
    5.0 "lenny" distribution. This update adds packages for lenny.

    For the oldstable distribution (lenny), this problem has been fixed in
    version 1.8.9-2+squeeze1. (Although the version number contains the
    string "squeeze", this is in fact an update for lenny.)

    For the stable distribution (squeeze), this problem has been fixed in
    version 1.8.11-2+squeeze2.

    For the unstable distribution (sid), this problem has been fixed in
    version 1.8.11-5.

    We recommend that you upgrade your ipmitool packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.10 (GNU/Linux)

    iQEcBAEBAgAGBQJO/v4FAAoJEOxfUAG2iX57ZxIH/3VOGKFEqkiYJyAeB96EA9d1 QKwRWxJmc+gsCB4cruNUWihCZpvgUVYHY7sRUqC+z5q5CidCehT6MRc+aBtbq0CI mroBMkTfMl135wYXtEabThDx/gHY+gKgzkqnalPEDAAsY6hMi3YGHeB7VXFClH/c mManIlimI9qbvBM/FvLCx0e43oBzNgdgbyhZpZO22CugMXwGQjZNfvAE+hfW2n25 fScxAtJTKcg9Wp2buuE7HYvn0dh9m/y8uw/mFwIYr7DLvwWRAcA+NdvCY4o863KT 0eJuPtK685CLFRwKGBKzuBflUBtb7fTpg2hW4GhhHQUF0aHz6Vz0Cpgf715I/bA=
    =xZPT
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)