PT-2025-33307 · Aide+2 · Aide+2
Raj3Shp
·
Published
2025-08-14
·
Updated
2025-09-22
·
CVE-2025-54409
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
AIDE versions 0.13 through 0.19.1
Description:
AIDE, an advanced intrusion detection environment, contains a null pointer dereference issue. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service.
Recommendations:
Update to version 0.19.2 or later.
As a workaround, remove the xattrs group from rules matching files on affected file systems.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aide
Linuxmint
Ubuntu