OpenBMC Security Advisory - CVE-2019-6260

Kun Zhao zkxz at hotmail.com
Tue Sep 22 02:09:48 AEST 2020


Thank you so much, Tom.



Thanks.

Kun

From: TOM JOSEPH<mailto:tomjose at linux.vnet.ibm.com>
Sent: Sunday, September 20, 2020 6:02 PM
To: Kun Zhao<mailto:zkxz at hotmail.com>; openbmc at lists.ozlabs.org<mailto:openbmc at lists.ozlabs.org>
Subject: Re: OpenBMC Security Advisory - CVE-2019-6260


Hello Kun,

The OpenBMC side of the fixes are captured in this link.

https://www.flamingspork.com/blog/2019/01/23/cve-2019-6260-gaining-control-of-bmc-from-the-host-processor/

Regards,
Tom
On 21-09-2020 05:17, Kun Zhao wrote:
Hi Team, This link here described the ‘pantsdown’ vulnerability found in OpenBMC,...
This Message Is From an External Sender
This message came from outside your organization.
Hi Team,

This link here described the ‘pantsdown’ vulnerability found in OpenBMC,
https://github.com/openbmc/openbmc/issues/3475

So what are the commits for fixing it?


Thanks.

Kun


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ozlabs.org/pipermail/openbmc/attachments/20200921/efa3ee56/attachment.htm>


More information about the openbmc mailing list