An ipmitool security update has been released for Oracle Linux 7 to address a buffer overflow in read_fru_area_section function in lib/ipmi_fru.c.
Oracle Linux Security Advisory ELSA-2020-0984
http://linux.oracle.com/errata/ELSA-2020-0984.html
The following updated rpms for Oracle Linux 7 have been uploaded to the
Unbreakable Linux Network:
x86_64:
bmc-snmp-proxy-1.8.18-9.el7_7.noarch.rpm
exchange-bmc-os-info-1.8.18-9.el7_7.noarch.rpm
ipmitool-1.8.18-9.el7_7.x86_64.rpm
SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/ipmitool-1.8.18-9.el7_7.src.rpm
Description of changes:
[0:1.8.18-9]
- Disable -fstrict-aliasing (RPMDiff issue)
[0:1.8.18-8]
- Backport fix for CVE-2020-5208