CVE-2011-4339
ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red Hat Enterprise Linux (RHEL) 6, Debian GNU/Linux, Fedora 16, and other products uses 0666 permissions for its ipmievd.pid PID file, which allows local users to…
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red Hat Enterprise Linux (RHEL) 6, Debian GNU/Linux, Fedora 16, and other products uses 0666 permissions for its ipmievd.pid PID file, which allows local users to kill arbitrary processes by writing to this file.
- CVSS 2.0
- 3.6 LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- ipmitool project/ipmitool
- Source
- secalert@redhat.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071575.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071580.htmlThird Party Advisory
- http://openwall.com/lists/oss-security/2011/12/13/1Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0123.htmlThird Party Advisory
- http://secunia.com/advisories/47173Broken Link
- http://secunia.com/advisories/47228Broken Link
- http://secunia.com/advisories/47376Broken Link
- http://www.debian.org/security/2011/dsa-2376Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:196Broken Link
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1814.htmlThird Party Advisory
- http://www.securityfocus.com/bid/51036Third Party Advisory, VDB Entry
- http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=742837Issue Tracking, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71763Third Party Advisory, VDB Entry
- http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071575.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071580.htmlThird Party Advisory
- http://openwall.com/lists/oss-security/2011/12/13/1Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0123.htmlThird Party Advisory
- http://secunia.com/advisories/47173Broken Link
- http://secunia.com/advisories/47228Broken Link
- http://secunia.com/advisories/47376Broken Link
- http://www.debian.org/security/2011/dsa-2376Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:196Broken Link
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1814.htmlThird Party Advisory
- http://www.securityfocus.com/bid/51036Third Party Advisory, VDB Entry
- http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=742837Issue Tracking, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71763Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.