Vulnerability Description
Red Hat Enterprise Linux (RHEL) 5 ships the rpm for the Advanced Intrusion Detection Environment (AIDE) before 0.13.1 with a database that lacks checksum information, which allows context-dependent attackers to bypass file integrity checks and modify certain files.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux | 5.0 |
Related Weaknesses (CWE)
References
- http://osvdb.org/40439
- http://secunia.com/advisories/26711Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0539.htmlPatchVendor Advisory
- http://www.securityfocus.com/bid/25542
- http://www.securitytracker.com/id?1018652
- https://bugzilla.redhat.com/show_bug.cgi?id=236923
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36452
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://osvdb.org/40439
- http://secunia.com/advisories/26711Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0539.htmlPatchVendor Advisory
- http://www.securityfocus.com/bid/25542
- http://www.securitytracker.com/id?1018652
- https://bugzilla.redhat.com/show_bug.cgi?id=236923
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36452
FAQ
What is CVE-2007-3849?
CVE-2007-3849 is a vulnerability with a CVSS score of 1.9 (LOW). Red Hat Enterprise Linux (RHEL) 5 ships the rpm for the Advanced Intrusion Detection Environment (AIDE) before 0.13.1 with a database that lacks checksum information, which allows context-dependent at...
How severe is CVE-2007-3849?
CVE-2007-3849 has been rated LOW with a CVSS base score of 1.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3849?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Linux.