Vulnerability CVE-2011-4339


Published: 2011-12-14   Modified: 2012-02-13

Description:
ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red Hat Enterprise Linux (RHEL) 6, Debian GNU/Linux, Fedora 16, and other products uses 0666 permissions for its ipmievd.pid PID file, which allows local users to kill arbitrary processes by writing to this file.

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.6/10
4.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
Partial
Affected software
Corey minyard -> Openipmi 

 References:
http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071575.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071580.html
http://openwall.com/lists/oss-security/2011/12/13/1
http://rhn.redhat.com/errata/RHSA-2013-0123.html
http://www.debian.org/security/2011/dsa-2376
http://www.mandriva.com/security/advisories?name=MDVSA-2011:196
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://www.redhat.com/support/errata/RHSA-2011-1814.html
http://www.securityfocus.com/bid/51036
http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf
http://xforce.iss.net/xforce/xfdb/71763
https://bugzilla.redhat.com/show_bug.cgi?id=742837

Copyright 2024, cxsecurity.com

 

Back to Top