LWN.net Logo

OpenIPMI: invalid permissions

Package(s):OpenIPMI CVE #(s):CVE-2011-4339
Created:January 14, 2013 Updated:January 17, 2013
Description: From the CVE entry:

ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red Hat Enterprise Linux (RHEL) 6, Debian GNU/Linux, Fedora 16, and other products uses 0666 permissions for its ipmievd.pid PID file, which allows local users to kill arbitrary processes by writing to this file.

Alerts:
Oracle ELSA-2013-0123 2013-01-12
Scientific Linux SL-Open-20130116 2013-01-16
CentOS CESA-2013:0123 2013-01-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds