OESA-2024-2049

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-2049
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2024-2049.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2024-2049
Upstream
Published
2024-08-23T11:08:56Z
Modified
2025-08-12T05:43:21.807902Z
Summary
booth security update
Details

Booth manages tickets which authorize cluster sites located in geographically dispersed locations to run resources. It facilitates support of geographically distributed clustering in Pacemaker.

Security Fix(es):

A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcrymdgetalgodlen(), it may allow an invalid HMAC to be accepted by the Booth server.(CVE-2024-3049)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP4 / booth

Package

Name
booth
Purl
pkg:rpm/openEuler/booth&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0-6.oe2003sp4

Ecosystem specific

{
    "src": [
        "booth-1.0-6.oe2003sp4.src.rpm"
    ],
    "aarch64": [
        "booth-1.0-6.oe2003sp4.aarch64.rpm",
        "booth-core-1.0-6.oe2003sp4.aarch64.rpm",
        "booth-debuginfo-1.0-6.oe2003sp4.aarch64.rpm",
        "booth-debugsource-1.0-6.oe2003sp4.aarch64.rpm"
    ],
    "x86_64": [
        "booth-1.0-6.oe2003sp4.x86_64.rpm",
        "booth-core-1.0-6.oe2003sp4.x86_64.rpm",
        "booth-debuginfo-1.0-6.oe2003sp4.x86_64.rpm",
        "booth-debugsource-1.0-6.oe2003sp4.x86_64.rpm"
    ],
    "noarch": [
        "booth-arbitrator-1.0-6.oe2003sp4.noarch.rpm",
        "booth-site-1.0-6.oe2003sp4.noarch.rpm",
        "booth-test-1.0-6.oe2003sp4.noarch.rpm"
    ]
}