OESA-2024-2050

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-2050
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2024-2050.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2024-2050
Upstream
Published
2024-08-23T11:07:31Z
Modified
2026-08-18T01:17:26Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
booth security update
Details

Booth manages tickets which authorize cluster sites located in geographically dispersed locations to run resources. It facilitates support of geographically distributed clustering in Pacemaker.

Security Fix(es):

A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.(CVE-2024-3049)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:24.03-LTS / booth

Package

Name
booth
Purl
pkg:rpm/openEuler/booth&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.1-6.oe2403

Ecosystem specific

{
    "aarch64": [
        "booth-1.1-6.oe2403.aarch64.rpm",
        "booth-core-1.1-6.oe2403.aarch64.rpm",
        "booth-debuginfo-1.1-6.oe2403.aarch64.rpm",
        "booth-debugsource-1.1-6.oe2403.aarch64.rpm"
    ],
    "noarch": [
        "booth-arbitrator-1.1-6.oe2403.noarch.rpm",
        "booth-site-1.1-6.oe2403.noarch.rpm",
        "booth-test-1.1-6.oe2403.noarch.rpm"
    ],
    "src": [
        "booth-1.1-6.oe2403.src.rpm"
    ],
    "x86_64": [
        "booth-1.1-6.oe2403.x86_64.rpm",
        "booth-core-1.1-6.oe2403.x86_64.rpm",
        "booth-debuginfo-1.1-6.oe2403.x86_64.rpm",
        "booth-debugsource-1.1-6.oe2403.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2024-2050.json"