RHSA-2022:0441: Important: aide security update
Advanced Intrusion Detection Environment (AIDE) is a utility that creates a database of files on the system, and then uses that database to ensure file integrity and detect system intrusions.Security Fix(es): aide: heap-based buffer overflow on outputs larger than B64BUF (CVE-2021-45417) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/aideto a version that resolves this vulnerability.Fixed in 0.16-14.el8_5.1 - Upgrade
Upgrade
redhat/aide-debuginfoto a version that resolves this vulnerability.Fixed in 0.16-14.el8_5.1 - Upgrade
Upgrade
redhat/aide-debugsourceto a version that resolves this vulnerability.Fixed in 0.16-14.el8_5.1 - Upgrade
Upgrade
redhat/aideto a version that resolves this vulnerability.Fixed in 0.16-14.el8_5.1.aa - Upgrade
Upgrade
redhat/aide-debuginfoto a version that resolves this vulnerability.Fixed in 0.16-14.el8_5.1.aa - Upgrade
Upgrade
redhat/aide-debugsourceto a version that resolves this vulnerability.Fixed in 0.16-14.el8_5.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0441?
The severity of RHSA-2022:0441 is classified as critical due to a heap-based buffer overflow vulnerability that can lead to system compromise.
How do I fix RHSA-2022:0441?
To fix RHSA-2022:0441, update the AIDE package to version 0.16-14.el8_5.1 or higher.
What software does RHSA-2022:0441 affect?
RHSA-2022:0441 affects the AIDE utility along with its debuginfo and debugsource packages on various architectures.
What type of vulnerability is described in RHSA-2022:0441?
RHSA-2022:0441 describes a heap-based buffer overflow vulnerability that can allow for unauthorized access or control over the affected system.
Is there a workaround for RHSA-2022:0441?
There is no recommended workaround for RHSA-2022:0441; updating to the patched version is the only safe approach.