A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2024-06-06 06:15
Updated : 2024-07-09 12:15
NVD link : CVE-2024-3049
Mitre link : CVE-2024-3049
CVE.ORG link : CVE-2024-3049
JSON object : View
Products Affected
clusterlabs
- booth
redhat
- enterprise_linux_for_ibm_z_systems_eus
- enterprise_linux_eus
- enterprise_linux_for_power_little_endian_eus
- enterprise_linux
- enterprise_linux_server_update_services_for_sap_solutions
- enterprise_linux_for_arm_64
- enterprise_linux_for_ibm_z_systems
CWE
CWE-345
Insufficient Verification of Data Authenticity