Description

A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.

INFO

Published Date :

2024-06-06T05:30:04.137Z

Last Modified :

2026-03-17T21:04:05.024Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2024-3049 vulnerability.

Vendors Products
Clusterlabs
  • Booth
Redhat
  • Enterprise Linux
  • Enterprise Linux Eus
  • Enterprise Linux For Arm 64
  • Enterprise Linux For Ibm Z Systems
  • Enterprise Linux For Ibm Z Systems Eus
  • Enterprise Linux For Power Little Endian Eus
  • Enterprise Linux Server Update Services For Sap Solutions
  • Rhel Aus
  • Rhel E4s
  • Rhel Eus
  • Rhel Tus

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact