CVE-2024-3049
Booth: specially crafted hash can lead to invalid hmac being accepted by booth server
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Productos afectados
boothRed Hat · Red Hat Enterprise Linux 10Red Hat · Red Hat Enterprise Linux 7Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRed Hat · Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRed Hat · Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRed Hat · Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRed Hat · Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRed Hat · Red Hat Enterprise Linux 8.8 Extended Update SupportRed Hat · Red Hat Enterprise Linux 9Red Hat · Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRed Hat · Red Hat Enterprise Linux 9.2 Extended Update Support¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://access.redhat.com/errata/RHSA-2024:3657https://access.redhat.com/errata/RHSA-2024:3658https://access.redhat.com/errata/RHSA-2024:3659https://access.redhat.com/errata/RHSA-2024:3660https://access.redhat.com/errata/RHSA-2024:3661https://access.redhat.com/errata/RHSA-2024:4400https://access.redhat.com/errata/RHSA-2024:4411https://access.redhat.com/security/cve/CVE-2024-3049https://bugzilla.redhat.com/show_bug.cgi?id=2272082https://github.com/ClusterLabs/booth/pull/142https://lists.debian.org/debian-lts-announce/2024/09/msg00037.htmlhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ERCFM3HXFJKLEMMWU3CZLPKH5LZAEDAN/