RHSA-2022:0440: Important: aide security update
Advanced Intrusion Detection Environment (AIDE) is a utility that creates a database of files on the system, and then uses that database to ensure file integrity and detect system intrusions.Security Fix(es): aide: heap-based buffer overflow on outputs larger than B64BUF (CVE-2021-45417) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/aideto a version that resolves this vulnerability.Fixed in 0.16-14.el8_4.1 - Upgrade
Upgrade
redhat/aide-debuginfoto a version that resolves this vulnerability.Fixed in 0.16-14.el8_4.1 - Upgrade
Upgrade
redhat/aide-debugsourceto a version that resolves this vulnerability.Fixed in 0.16-14.el8_4.1 - Upgrade
Upgrade
redhat/aideto a version that resolves this vulnerability.Fixed in 0.16-14.el8_4.1.aa - Upgrade
Upgrade
redhat/aide-debuginfoto a version that resolves this vulnerability.Fixed in 0.16-14.el8_4.1.aa - Upgrade
Upgrade
redhat/aide-debugsourceto a version that resolves this vulnerability.Fixed in 0.16-14.el8_4.1.aa - Compensating control
Apply the AIDE security update for the heap-based buffer overflow on outputs larger than B64_BUF (CVE-2021-45417) as described in the referenced advisory/article ("aide security update").
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0440?
The severity of RHSA-2022:0440 is classified as important.
How do I fix RHSA-2022:0440?
To fix RHSA-2022:0440, update the AIDE package to version 0.16-14.el8_4.1 or later.
What systems are affected by RHSA-2022:0440?
RHSA-2022:0440 affects systems running AIDE versions prior to 0.16-14.el8_4.1.
What type of vulnerability is addressed in RHSA-2022:0440?
RHSA-2022:0440 addresses a heap-based buffer overflow vulnerability in the AIDE utility.
Is there any specific deployment advice for RHSA-2022:0440?
It is advised to update AIDE immediately to mitigate potential exploitation of the vulnerability.