Untriaged
Permalink
CVE-2024-3049
5.9 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): HIGH
- Availability impact (A): NONE
Booth: specially crafted hash can lead to invalid hmac being accepted by booth server
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
References
Affected products
booth
- ==1.0-283.1
- *
Matching in nixpkgs
pkgs.libsForQt5.booth
Camera application
pkgs.plasma5Packages.booth
Camera application
Package maintainers
-
@milahu Milan Hauth <milahu@gmail.com>