First published: Mon Feb 07 2022(Updated: )
Advanced Intrusion Detection Environment (AIDE) is a utility that creates a database of files on the system, and then uses that database to ensure file integrity and detect system intrusions.<br>Security Fix(es):<br><li> aide: heap-based buffer overflow on outputs larger than B64_BUF (CVE-2021-45417)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/aide | <0.16-11.el8_2.1 | 0.16-11.el8_2.1 |
redhat/aide | <0.16-11.el8_2.1 | 0.16-11.el8_2.1 |
redhat/aide-debuginfo | <0.16-11.el8_2.1 | 0.16-11.el8_2.1 |
redhat/aide-debugsource | <0.16-11.el8_2.1 | 0.16-11.el8_2.1 |
redhat/aide-debuginfo | <0.16-11.el8_2.1 | 0.16-11.el8_2.1 |
redhat/aide-debugsource | <0.16-11.el8_2.1 | 0.16-11.el8_2.1 |
redhat/aide | <0.16-11.el8_2.1 | 0.16-11.el8_2.1 |
redhat/aide-debuginfo | <0.16-11.el8_2.1 | 0.16-11.el8_2.1 |
redhat/aide-debugsource | <0.16-11.el8_2.1 | 0.16-11.el8_2.1 |
redhat/aide | <0.16-11.el8_2.1.aa | 0.16-11.el8_2.1.aa |
redhat/aide-debuginfo | <0.16-11.el8_2.1.aa | 0.16-11.el8_2.1.aa |
redhat/aide-debugsource | <0.16-11.el8_2.1.aa | 0.16-11.el8_2.1.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:0456 is classified as critical due to the presence of a heap-based buffer overflow vulnerability in AIDE.
To fix RHSA-2022:0456, users should update the AIDE package to version 0.16-11.el8_2.1 or later.
RHSA-2022:0456 can allow an attacker to exploit the heap-based buffer overflow to gain unauthorized access or disrupt system integrity.
Versions of AIDE prior to 0.16-11.el8_2.1 are affected by the vulnerability outlined in RHSA-2022:0456.
There is no official workaround for RHSA-2022:0456; upgrading to the patched version is the recommended solution.