cbcvebase.
CVE-2021-45417
published 2022-01-20

CVE-2021-45417: AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.

Affected

21 ranges
VendorProductVersion rangeFixed in
advanced_intrusion_detection_environment_projectadvanced_intrusion_detection_environment0.13 – 0.17.3
aideaide>= 0 < 0.17.3-4+deb11u10.17.3-4+deb11u1
aideaide>= 0 < 0.17.4-10.17.4-1
aideaide>= 0 < 0.17.4-10.17.4-1
aideaide>= 0 < 0.17.4-10.17.4-1
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianaide< aide 0.17.4-1 (bookworm)aide 0.17.4-1 (bookworm)
debiandebian_linux
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatovirt-node
redhatvirtualization_host

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH