CVE-2007-3849: Low severity redhat Enterprise Linux vulnerability
Description of problem: Several bugs have been fixed in recent version of aide (0.13.1) that we should pull in to RHEL5. The upstream version of aide has all but 1 of our aide patches, so rebasing would allow us to simplify things. 0.13.1 is overwhelmingly the work that we did for xattr support. But there are a few bug fixes.
Version-Release number of selected component (if applicable): aide-0.12-8.el5
Other sources
Red Hat Enterprise Linux (RHEL) 5 ships the rpm for the Advanced Intrusion Detection Environment (AIDE) before 0.13.1 with a database that lacks checksum information, which allows context-dependent attackers to bypass file integrity checks and modify certain files.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3849?
CVE-2007-3849 is categorized as a moderate severity vulnerability.
How do I fix CVE-2007-3849?
To fix CVE-2007-3849, update the AIDE package to version 0:0.13.1-2.0.4.el5 or later.
What systems are affected by CVE-2007-3849?
CVE-2007-3849 affects Red Hat Enterprise Linux (RHEL) 5.0 in both desktop and server configurations.
What vulnerability does CVE-2007-3849 exploit?
CVE-2007-3849 exploits a lack of checksum information in the AIDE database, allowing attackers to bypass file integrity checks.
Is CVE-2007-3849 specific to a certain version of AIDE?
Yes, CVE-2007-3849 specifically affects AIDE versions before 0.13.1.