Vulnerabilities > CVE-2021-45417 - Out-of-bounds Write vulnerability in multiple products
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH local
low complexity
advanced-intrusion-detection-environment-project
redhat
fedoraproject
canonical
debian
CWE-787
Summary
AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- http://www.openwall.com/lists/oss-security/2022/01/20/3
- http://www.openwall.com/lists/oss-security/2022/01/20/3
- https://lists.debian.org/debian-lts-announce/2022/01/msg00024.html
- https://lists.debian.org/debian-lts-announce/2022/01/msg00024.html
- https://security.gentoo.org/glsa/202311-07
- https://security.gentoo.org/glsa/202311-07
- https://www.debian.org/security/2022/dsa-5051
- https://www.debian.org/security/2022/dsa-5051
- https://www.ipi.fi/pipermail/aide/2022-January/001713.html
- https://www.ipi.fi/pipermail/aide/2022-January/001713.html
- https://www.openwall.com/lists/oss-security/2022/01/20/3
- https://www.openwall.com/lists/oss-security/2022/01/20/3