CVE-2020-5208

CVE Details

Release Date:2020-02-05

Description


It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19.

See more information about CVE-2020-5208 from MITRE CVE dictionary and NIST NVD


CVSS v3.0 metrics


NOTE: The following CVSS v3.0 metrics and score provided are preliminary and subject to review.

Base Score: 8.8 Base Metrics: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Access Vector: Network Attack Complexity: Low
Privileges Required: Low User Interaction: None
Scope: Unchanged Confidentiality Impact: High
Integrity Impact: High Availability Impact: High

Errata information


PlatformErrataRelease Date
Oracle Linux version 6 (ipmitool)ELSA-2020-13312020-04-07
Oracle Linux version 7 (ipmitool)ELSA-2020-09842020-03-27
Oracle Linux version 8 (ipmitool)ELSA-2020-09812020-03-26
Oracle VM version 3.3 (ipmitool)OVMSA-2020-00122020-04-14
Oracle VM version 3.4 (ipmitool)OVMSA-2020-00122020-04-14



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete