-----BEGIN PGP SIGNED MESSAGE-----
 Hash: SHA1
 
 - -------------------------------------------------------------------------
 Debian Security Advisory DSA-2376-2                   security@debian.org
 http://www.debian.org/security/                           Thijs Kinkhorst
 December 31, 2011                      http://www.debian.org/security/faq
 - -------------------------------------------------------------------------
 
 Package        : ipmitool
 Vulnerability  : insecure pid file
 Problem type   : local
 Debian-specific: no
 CVE ID         : CVE-2011-4339
 Debian Bug     : 651917
 
 It was discovered that OpenIPMI, the Intelligent Platform Management
 Interface library and tools, used too wide permissions PID file,
 which allows local users to kill arbitrary processes by writing to
 this file.
 
 The original announcement didn't contain corrections for the Debian
 5.0 "lenny" distribution. This update adds packages for lenny.
 
 For the oldstable distribution (lenny), this problem has been fixed in
 version 1.8.9-2+squeeze1. (Although the version number contains the
 string "squeeze", this is in fact an update for lenny.)
 
 For the stable distribution (squeeze), this problem has been fixed in
 version 1.8.11-2+squeeze2.
 
 For the unstable distribution (sid), this problem has been fixed in
 version 1.8.11-5.
 
 We recommend that you upgrade your ipmitool packages.
 
 Further information about Debian Security Advisories, how to apply
 these updates to your system and frequently asked questions can be
 found at: http://www.debian.org/security/
 
 Mailing list: debian-security-announce@lists.debian.org
 -----BEGIN PGP SIGNATURE-----
 Version: GnuPG v1.4.10 (GNU/Linux)
 
 iQEcBAEBAgAGBQJO/v4FAAoJEOxfUAG2iX57ZxIH/3VOGKFEqkiYJyAeB96EA9d1
 QKwRWxJmc+gsCB4cruNUWihCZpvgUVYHY7sRUqC+z5q5CidCehT6MRc+aBtbq0CI
 mroBMkTfMl135wYXtEabThDx/gHY+gKgzkqnalPEDAAsY6hMi3YGHeB7VXFClH/c
 mManIlimI9qbvBM/FvLCx0e43oBzNgdgbyhZpZO22CugMXwGQjZNfvAE+hfW2n25
 fScxAtJTKcg9Wp2buuE7HYvn0dh9m/y8uw/mFwIYr7DLvwWRAcA+NdvCY4o863KT
 0eJuPtK685CLFRwKGBKzuBflUBtb7fTpg2hW4GhhHQUF0aHz6Vz0Cpgf715I/bA=
 =xZPT
 -----END PGP SIGNATURE-----
 
 
 -- 
 To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
 with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
 Archive: http://lists.debian.org/20111231122117.DCE4559DF0@kinkhorst.com