OESA-2022-1523
Dashboard / Vulnerabilities / OESA-2022-1523
Summary: aide security update
Details: AIDE (Advanced Intrusion Detection Environment) is a file and directory integrity checker. It creates a database from the regular expression rules that it finds from the config file(s). Once this database is initialized it can be used to verify the integrity of the files. Security Fix(es): AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.(CVE-2021-45417)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1523, https://nvd.nist.gov/vuln/detail/CVE-2021-45417
Affected packages
Package
Name: aide
Purl: pkg:rpm/openEuler/aide&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
