Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-45417

Опубликовано: 20 янв. 2022
Источник: redhat
CVSS3: 7.5

Описание

AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.

A heap-based buffer overflow vulnerability in the base64 functions of AIDE, an advanced intrusion detection system. An attacker could crash the program and possibly execute arbitrary code through large (<16k) extended file attributes or ACL.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9aideNot affected
Red Hat Enterprise Linux 6 Extended Lifecycle SupportaideFixedRHSA-2022:047208.02.2022
Red Hat Enterprise Linux 7aideFixedRHSA-2022:047308.02.2022
Red Hat Enterprise Linux 8aideFixedRHSA-2022:044107.02.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsaideFixedRHSA-2022:046408.02.2022
Red Hat Enterprise Linux 8.2 Extended Update SupportaideFixedRHSA-2022:045607.02.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportaideFixedRHSA-2022:044007.02.2022
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7redhat-virtualization-hostFixedRHSA-2022:126307.04.2022
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8redhat-virtualization-hostFixedRHSA-2022:054015.02.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2041489aide: heap-based buffer overflow on outputs larger than B64_BUF

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 3 лет назад

AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.

CVSS3: 7.8
nvd
больше 3 лет назад

AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.

CVSS3: 7.8
debian
больше 3 лет назад

AIDE before 0.17.4 allows local users to obtain root privileges via cr ...

suse-cvrf
больше 3 лет назад

Security update for aide

suse-cvrf
больше 3 лет назад

Security update for aide

7.5 High

CVSS3