security advisoryaidedebian
Rajesh Pangare discovered two vulnerabilities in aide, an advanced intrusion detection system. A local attacker can take advantage of these flaws to hide the addition or removal of a file from the the report, tamper with the log output, or cause aide to crash during report . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5977-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso August 14, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : aide CVE ID : CVE-2025-54389 CVE-2025-54409 Rajesh Pangare discovered two vulnerabilities in aide, an advanced intrusion detection system. A local attacker can take advantage of these flaws to hide the addition or removal of a file from the the report, tamper with the log output, or cause aide to crash during report printing or database listing. For the oldstable distribution (bookworm), these problems have been fixed in version 0.18.3-1+deb12u4. For the stable distribution (trixie), these problems have been fixed in version 0.19.1-2+deb13u1. We recommend that you upgrade your aide packages. For the detailed security status of aide please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/aide Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A pair of weaknesses discovered in aide enables local assailants to alter log results and elevate security threats.. Debian security advisory, aide vulnerabilities, intrusion detection system. . Severity: Important. LinuxSecurity.com Team
Aug 14, 2025
•Important
Debian