First published: Tue Feb 08 2022(Updated: )
Advanced Intrusion Detection Environment (AIDE) is a utility that creates a database of files on the system, and then uses that database to ensure file integrity and detect system intrusions.<br>Security Fix(es):<br><li> aide: heap-based buffer overflow on outputs larger than B64_BUF (CVE-2021-45417)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/aide | <0.14-11.el6_10.1 | 0.14-11.el6_10.1 |
redhat/aide | <0.14-11.el6_10.1 | 0.14-11.el6_10.1 |
redhat/aide-debuginfo | <0.14-11.el6_10.1 | 0.14-11.el6_10.1 |
redhat/aide-debuginfo | <0.14-11.el6_10.1 | 0.14-11.el6_10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:0472 is classified as important.
To fix RHSA-2022:0472, you should update the 'aide' package to version 0.14-11.el6_10.1.
RHSA-2022:0472 addresses a heap-based buffer overflow vulnerability in the AIDE utility.
Versions of 'aide' prior to 0.14-11.el6_10.1 are affected by RHSA-2022:0472.
There is no specific workaround for RHSA-2022:0472; applying the security update is recommended.