CVE-2021-45417: Buffer Overflow
A heap-based buffer overflow vulnerability in base64 functions of AIDE, an advanced intrusion detection system. An attacker could crash the program and possibly execute arbitrary code through large (<16k) extended file attributes or ACL. A local user might exploit this flaw for root privilege escalation.
Other sources
A heap-based buffer overflow vulnerability in the base64 functions of AIDE, an advanced intrusion detection system. An attacker could crash the program and possibly execute arbitrary code through large (<16k) extended file attributes or ACL.
AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this AIDE vulnerability?
The vulnerability ID of this AIDE vulnerability is CVE-2021-45417.
What is the severity of CVE-2021-45417?
The severity of CVE-2021-45417 is high with a severity value of 7.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by using crafted file metadata to cause a heap-based buffer overflow in the base64 functions of AIDE.
What is the potential impact of this vulnerability?
The potential impact of this vulnerability is that an attacker could crash the program and potentially execute arbitrary code.
How do I fix CVE-2021-45417?
To fix CVE-2021-45417, you should update AIDE to version 0.17.4 or apply the appropriate remedy provided by your software vendor.