A heap-based buffer overflow vulnerability in base64 functions of AIDE, an advanced intrusion detection system. An attacker could crash the program and possibly execute arbitrary code through large (<16k) extended file attributes or ACL. A local user might exploit this flaw for root privilege escalation.
The default aide.conf file in Advanced Intrusion Detection Environment (AIDE) before 0.71 on FreeBSD before 2002-08-28 does not properly check subdirectories, which could allow local users to bypass detection.