Lucene search

K
redhatRedHatRHSA-2011:1814
HistoryDec 13, 2011 - 12:00 a.m.

(RHSA-2011:1814) Moderate: ipmitool security update

2011-12-1300:00:00
access.redhat.com
12

0.0004 Low

EPSS

Percentile

10.1%

The ipmitool package contains a command line utility for interfacing with
devices that support the Intelligent Platform Management Interface (IPMI)
specification. IPMI is an open standard for machine health, inventory, and
remote power control.

It was discovered that the IPMI event daemon (ipmievd) created its process
ID (PID) file with world-writable permissions. A local user could use this
flaw to make the ipmievd init script kill an arbitrary process when the
ipmievd daemon is stopped or restarted. (CVE-2011-4339)

All users of ipmitool are advised to upgrade to this updated package, which
contains a backported patch to correct this issue. After installing this
update, the IPMI event daemon (ipmievd) will be restarted automatically.