-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 09 Feb 2020 15:55:58 +0100 Source: ipmitool Binary: ipmitool Architecture: source amd64 Version: 1.8.14-4+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Jörg Frings-Fürst <debian@jff-webhosting.net> Changed-By: Markus Koschany <apo@debian.org> Description: ipmitool - utility for IPMI control with kernel driver or LAN interface Changes: ipmitool (1.8.14-4+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2020-5208: Christopher Ertl found that multiple functions in ipmitool neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. Checksums-Sha1: 1578d37973688bb6c379ab1ff222348f2403a761 2133 ipmitool_1.8.14-4+deb8u1.dsc dee694514559cbd6ff4f0d21264c05d29ce48902 917886 ipmitool_1.8.14.orig.tar.gz ba81c52013f7f54d9e0cbe58c7b0d0dbc4914811 19148 ipmitool_1.8.14-4+deb8u1.debian.tar.xz 62fd837344479dda9e8f67ddb9c07aada471baa3 375846 ipmitool_1.8.14-4+deb8u1_amd64.deb Checksums-Sha256: 3d52097278ce6b230866877b53d47fcbe8fb94110b08bbc724eb0a5edb349989 2133 ipmitool_1.8.14-4+deb8u1.dsc fe9bce4587f83fe0fd7c4d86fd3241fe41cb661ebc5c7321128d59cc295874ab 917886 ipmitool_1.8.14.orig.tar.gz 74725389265232666bf9bae29c61264e5e353864eff74263d0090905aa88d2e1 19148 ipmitool_1.8.14-4+deb8u1.debian.tar.xz bac0e0223acc2b4a466f572ff8b66573972810dbd51757ee38174a562f2fe8e2 375846 ipmitool_1.8.14-4+deb8u1_amd64.deb Files: 170da60df06e41c499eeda7addfaf174 2133 utils optional ipmitool_1.8.14-4+deb8u1.dsc 13d216fe74999717338dcd1bb2ed478f 917886 utils optional ipmitool_1.8.14.orig.tar.gz 9e21f81731175964d7f416e3dbedc9c2 19148 utils optional ipmitool_1.8.14-4+deb8u1.debian.tar.xz 0c02ea3a91de12127e444ba1e530cf58 375846 utils optional ipmitool_1.8.14-4+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl5AJL5fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkapsP/j7OrQX0y2Rvl2fxnefOjNBOmpvbkspHbEgF AXZ8iAwTHAR1ZIjgJNErZ13UE5jsePZeE/oaEFkZgHIw9I3OfuH6N1gQ3MM8yiiy IQye2IKSEK3N/sfD5qFBzaY1htYDoxuNUPCZDOwBveQ6Jb1yANS4yAPovIiak3qo tpl8V2WjrsO+xFVuQJbE66MEmrSj3LUfIzQez3PWKAtEcB6ImcvhnPXtrPHtg740 1H0d8uP9+nJLgcw04BAOHPqWvx9O/PXfX9ck5Fe1VOtpCDZHhiCNClZGBMXcix2T xIclCAd9ELeLoNBg9NtDpzHjxtNSfNX1VKiVL1cKYjAWHASLU4ngMxKhROmdNNJ4 cch+xxuQbGYtRs92nEMeXuHKdVWwZCs2AkD46bR63CF5Lbu/1gujAAbBZo4BhcuJ e78bHKfojozsTfaSRvWyOUYrQwB/6ZYiLVUpVRs+IyZs9jdcexg51J+26R8oowXy sbIzcx3gyQPNUP9DxkMGqCiLEee0IIY23lnrpnOMPDMU2GUGsv1SXhvASSWqdhpr +aGYS+VD4dAqmTGx9vocP62k1X9YHA52wevdCmaXOxyLqWH+0IOSsMj8sPniZMsr m0E89oAOg1wy8BdV+zlsTlDLip0GE0qgCLrcuC9TZf9HQlaIH4m697akvYpUT+TL iR6sDnEF =b22p -----END PGP SIGNATURE-----