Skip to content

Security: aide/aide

Security

SECURITY.md

Security Policy

Supported Versions

Generally the latest release (e.g. v0.18.x) is supported with security updates.

Reporting a Vulnerability

PLEASE DON'T DISCLOSE SECURITY-RELATED ISSUES PUBLICLY

If you have found a security issue in AIDE, please disclose it privately and responsibly by sending a PGP encrypted email (no HTML please) to hannes(at)vonhaugwitz(dot)com.

You should receive a response within a few days. If for some reason you do not, please follow up via email to ensure we received your original message.

Please add the address above as safe senders in your email client.

Your message should include any of the following (if possible):

  • type of issue (e.g. buffer overflow)
  • affected versions
  • step-by-step instructions to reproduce the issue (if known)
  • proof-of-concept or exploit code (if available)
  • impact of the issue, including how an attacker might exploit the issue
  • your PGP key
  • your name and affiliation (if any), if you wish to get recognition
  • whether the vulnerability is public or known to third parties (if so please provide details)

Encrypt your mail (preferably in PGP/MIME format) using the following PGP key:

pub   rsa4096/0xF6947DAB68E7B931 2011-06-28 [C]
      Key fingerprint = 2BBB D30F AAB2 9B32 53BC  FBA6 F694 7DAB 68E7 B931
uid                   [ultimate] Hannes von Haugwitz <hannes@vonhaugwitz.com>
uid                   [ultimate] Hannes von Haugwitz <hvhaugwitz@debian.org>
sub   rsa3072/0x18EE86386022EF57 2011-06-28 [S]
sub   rsa3072/0x57C198E495A601C7 2011-06-28 [E]
sub   rsa3072/0xF4B483CB268B1790 2011-06-28 [A]
-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBE4J+9wBEADaOHrCu7XWLSs4RzDPQMv4vCdtMASJJFBzXZzxaqUaDTZpwOxR
6wMw8PFwC0UphzbX/UBSZ1Q+31Xq0sCMOBfKA4hFVY7uDwLqommVVrctlvpcKNa4
O1lov0pg7yessUnaidO+DoJ2SJW7pvvXcI6FWLXNENzsOWL8zzgIXrkU73hV3moL
yrfPXwwj+tppSXeOg7HgxRSUfoqKwVkCdtQEyvBI1ue33jhwL1/9RUg4m8ph2unk
QXJIloivIu7Yv0S3TgcbNzJJ7V1B/M+v1EjVKhtImp1iocxLctzE5d9G2MKfpAkg
c/9McV9+KdflpS5gWZIMHHKnsJ0dzh/LZGKi47298W0h4ce3BM9gGetNyu1f7hQi
9pumoUeMymkuPeuQv3NaecLY9LSvAF9KLWRwXXxoihDYlr4cbpMyS4jT/nFCd3cu
5CXBBIoeO2w+bpxs16LD83MQdg9vRKC77sgOC/O+gWIJDh31l4aystomOOHek069
pWoOb1aIbFtaSYtVntyZ8DmyoDWvB3b/PXbxle5CkN/NPw9VDjZxqPSliTdUf1LG
EDPx22fFTHfMhjgC5XqceoWWCmvqy+4grHaLSkYKimI1DlhhVH6jYnhfBzcWDb4n
LyoRGOAKa0FurW5//I78wpkZCvTA4lTvJPHBI77+HlfiDjuuCMdFbyp6GQARAQAB
tCxIYW5uZXMgdm9uIEhhdWd3aXR6IDxoYW5uZXNAdm9uaGF1Z3dpdHouY29tPokC
VwQTAQoAQQIbAQULCQgHAwUVCgkICwUWAgMBAAIeAQIXgAIZARYhBCu70w+qspsy
U7z7pvaUfato57kxBQJqJRpRBQkf+TT1AAoJEPaUfato57kxaswQALXSA6zk3g9c
lxIHftyF6+zKhME36400cwHratD0Hu2mQsR/jHwmIJx2K+qn50teMk9IafFzs58X
3G0ooU6iweqILoQCacL64GYziXpb8PkkQZAVA9hERqRgvHugfNWxgoGw1RqQFRma
KMBmyrkgmpYUS3vtqLNXNuBcqGK0ukQiHyQ0hwXonjHhEIDRxVKnc6dhcUjuurVu
WIdvYvycWuoKPdU/k6ZlS3PbzWIpnwXeijwkVQxuBKBBWVo6wp52mknL7R2Ex/Dy
9PwFkOzTkVKgr6b5gn7iQKfxw5jzvM8JeNBAQdA9vrF+IiiGsAnHE7UwluGcpZaf
4S74AKkUNepPHVvgZA/MwQJTi9oIz+Irv43mq0sPplUnHlyJHchz9GjQXF1dD3sQ
1Ghk4X1Ue6LvK0UXtypZmVvDNMVMaMss90gYutMLH9PYwDiFyrF2jj1yufXu5Fhx
T4R81x8TCTXrks3bumcj/8+fBUtHtWa0soMc6wrQZUbg9GvRIeq4gnbCyHye95uI
qla/+z0nwVql5VuCwK/4tEZvE2wdTx6DfkyB2iY3Ufsd9f7U3q1aIIt65sIh0HzE
J9tu82HKw2OXBUpzDKp2zXH4Cp5hy9nyv71YT+VuPqy+bVX7fK98Tock0voLi1sy
yHjBz0bt2ai79SgRv4ekzXNEvz/UaIfNtCtIYW5uZXMgdm9uIEhhdWd3aXR6IDxo
dmhhdWd3aXR6QGRlYmlhbi5vcmc+iQJUBBMBCgA+AhsBBQsJCAcDBRUKCQgLBRYC
AwEAAh4BAheAFiEEK7vTD6qymzJTvPum9pR9q2jnuTEFAmolGlIFCR/5NPUACgkQ
9pR9q2jnuTEG8w//XmSDoqQFCwd3dzKdW9x8qH8ZE8VNy0lYmrZw5pTLtOVhK6H+
lStzLTes7rEE1duUYxTPZoUun1hYlOsew/D6DIZvCdPqqb4oHFoGcDckfwS+2sUA
hoqac8uLG7HEKZYR/Buq2wkQwSbrRJBxG3As1fXxCnqwpsHo7rWtv/r4i6MUDold
7bAulCodFt3zrIR91gbs12uURFxy5jwkuutKmDsxZbslmLppxDlX7DrUfPCVHrzI
X1lAFip0psn3ClxmPNFqh2D808EK/J7xR5ZJcMLQ/TZGZD05BLitiwnawW7E1BAa
8ESLz5wivGezKqfSQOrpH0LUTwbQRh0RtuEalORQNUq3yNq8kf1tLJ0NsQFKHhez
n3WbmMOM+iIXyEP6814FSWJwuxtU1O7pdCZj7ZIBCJSGU7UfeZ5m0Ml7M0vOITBn
EaixWTkixbFQWhn2HAuQ7jPmrNVYJv3EW7ftVFMWZXcI6pDusngqDQGa22MwlRCX
CTCol64+UvX3wrgS/MuPcBX5eEGgfaOSWLGqXCL4/oXG/5dQwMO4MS+6/WEZueYh
hRn/0tmaOi8uIX+OXluspE2kA8tx3I4NQ03//7r+OgqQyBekL04nkhWydiFowiOr
Z7TUDZ/ts1oMKhnb0HjjOIWI85M2J26WJNYm9dKJPD+KT8u1yo2mRqppby+5AY0E
Tgn8cgEMAM6Nv21neMk8LSH2HPDirz0w0UWnpkqdmk1oPCw+b4SILyJwNnOi1G5N
OP9ubGLDgr1HIzVnG18k429rScgKK9gddT0dqFmmQnFvGAVaMQPTNQVZFvPiZ27j
DjwupwcN5vnMlZ6Hqwk4vwTDqVi0qQ3lOnPYa9p4VLRmZO5a1A1F+CJsczifmohM
nCsbcoB1iqBV3/YgQa/RW2Gqjecq/g9fmvIMgj0+O03PAp4KGizRAhcBTkebpVrR
GedM9wFtn+rXNJ0PzVt0Ez2yJ+0FIKn0o/dT40h6oSDdXOce0WIW+jcAkKtpzTkf
9bleRqfRDYz2tvLbRrij1EO5POj6Z54BA/lzTCZFz9IRkrvOHyzPr6C5aP1BOJGd
NhWLXNuuxykMFyoQ591qSetDFH6egnjIFaIR7TNZITew49cZi1ZcYaIEb00EdjlR
6gMzX/WOA/tptfAcaK4r8A5NnDh0cxcaGQPN9WMtcyeWIJogFFMTC07YXB13l4yU
d/WfXI2l6QARAQABiQPbBBgBCgAmAhsCFiEEK7vTD6qymzJTvPum9pR9q2jnuTEF
AmolGngFCR4Wr4YBqcDdIAQZAQgABgUCTgn8cgAKCRAY7oY4YCLvV/x3C/44CpgL
VRUZT8bxDp7ZjIpyxTB43f+tpGlykSFMYS3/Cw/i7ar1fjoAeVonXAp0PpqeuJ9w
+p9r3UWPZeVlmibYybLujnNDnV6RmeNtzc4HUtgPP/s7rynU6RFX46T5YRUBo/aC
hjFcWVi+YUaNfBdgaKyf4INWtuNTndLXlOJkuqGCikKOuuwReJ4pvs49whVj9Nug
jsotEf4/+tzsrCIWLtSF2BI/Fz0xV2vlmCzsB5fN4nC/ksaaXAL7jHwaUbTMLJ3W
9pcqBzyUd5CEMlE0bwPihyVItLLdTErbuN7M5v3iYSRakRzm0xCpyb01Ho/KWsTW
znaGh3XK6e05Avss8mIaju+Zf/Vk+oLNzGqI+YAgczWyK82yDbuxXfWauBI32nmF
XDwqN8pvPGGEm8BgMQxfKnV0mt3BezPTYBSuPw22+wVbao3xMJSIlIbFitw2ZOSL
mit64IYYVGaWr3awn65MSK/Db9SRaGv52gOR6ylDul7wkjNE8ohlaos0y9sJEPaU
fato57kxqOcP/2kfoDOWEWyqSRWgXJLW/QdORTBdNdt1TK7rw0dzO621/JNoySV9
27wK52AumyKWtJFe9LuXsp3T/CPYFwBsLVoQ50AMKO/v5FOjxuAwAxMe3yYVzbza
Jix/gbtKAAbPtApjsbuc6Vbfe0XgCxqJBISe+fmZq7y9wW9fcPjsNeigKUH21rOJ
pHYvpIcyZHU7mzK5Dc0pbqcNRzEotzUjc2HdCl8XmMfrctGRQnE6tTBeRU4es+jG
do8uRwxdRlORWm6H+9RLQU/eZNvZqwsQitn9BdATQme0uJTrH5OpLG02i5cKc9Bz
wNu04PAL6Gj7Hk+lmfH/+DTDKaygcY1viCQ+anyIrrh3ZXx1+1bWx6ye7LtGnfcG
mMhCet6TcA9zP1O+3xEmrUZE792bPfuU+1kMyPk+xRd+7suF5DWGEGx/IvQrNLU5
C9zTjOUWtXDxqrO9+bKFrKXtlNdB9RdOgGWoAbWbh4fX/m/AKb86grt6dDM5/sqm
jjO9U7pfo4eWHzHhA86iUCrKvjiulhfAsz0mUgjVPZhq2rTVylyveLqUDPq4Cbeq
x9z5eS/1vQjWzCUTWDYLzHPOWA0GgxO7jy0lrgJc+23KpJF3XpSMb6OYqtwT8NB2
D0V4qtQbAf2HlKDkb+lY9Y4QfjpALgdNdlu3/pNxoiYbeUrKzsyLxQlcuQGNBE4J
/TQBDACoLGAOK8w/Mv1B3SZN/mfUYXgjJnOS1lqCNdKRG8MVQQCBVEe9QPU8yavh
/MpraEvPZhz6WSg7k1pHNMbKsDfv80ZX5WM95uMN69nmF/l+qo+eBJU8YIHWabkv
MSWTBeD1roo8CwHOl102ajgo0XzhCqeb4MkUCZCZxdTaoHcD+IW+4IbajozgzTYV
EQnyJdZwmB/EjRAncKDNCDoimHzjENQ9KOO/cPoGTFNfy9czoAmOY8gWt7b4wELD
Mx/tP06V3n9Zjpxx+sBId9xDv+Yd+JSJHbNk8FxQtRtZVGNv7SP0rIWv3AP+d93k
t/djtijzFTS5JxFViJtjwsDMdXQYnb+ReP4Jza5gLr/8gjbCRlLv/Bh1D9SyXFmf
tEcZyhJIUU2b2ybdCkwg/BdouoQxHN94bESy686djt1wiXLZa6s4jiFuMA3qfF+K
HDIbdjMBZzi0+XgJwwiqLlRkvLiG8/mGCijwFY+zzZ2lxKCOAEo8bUexOBz16Sw1
Fj55vgsAEQEAAYkCPAQYAQoAJgIbDBYhBCu70w+qspsyU7z7pvaUfato57kxBQJq
JRqHBQkeFq7TAAoJEPaUfato57kx9+4QALXv6OX2edJw3bWI6lnn3RUYdDzp+5tb
pFCURxwvIqNyDEDwUzz7E7JtUwwsno8kkcw623sEwScLM2nhWfOjUV6YQAFsauq+
L0Jt4eeO8xWDAscYAcPCRpOiTssmb8OvBg5W0rijmApVfM0LvoGIAJz3P5RKVW3P
KQm7/p7BStiS5u3TBHyVbai4NEEAiHApibQVoCOtMm9jKqYWj/eNjvZjiK1QpegJ
87gCymYu5f5fBFTCIBRwP1vJ6eq+wTSA5OoXXagN9tXmHPlU6PZRcLk3t/t02PEi
qg9Zn88FD3XgTNhusw7IIB7gZhhQNgSost6R2en4SZdkMkQ+z8yuejKgBMVSQzzo
eN9eFSztThFLPMD5pZLgQOElD5keh/vfE4NP1FmgfqXtcLcdcnf5vEcWbfyOPDAh
NwyJN2HL6zvJZf0iPPBGoIdL1uvjdtP9X9Jdz1Wb2kxYoq1lC8+U/9k9jBdhBP23
BB0cO0iNuBJMzv8YcQyB+4QPpf2XVaMSs9Fcm6MvJKq8nwflh4q8GOGaOrwt6eH4
2oi7UHZ0apN0XiLVC6MjK5nF1poLvIoTNeX59dBFdQ5Qjrp71sdUrrFMFqscJZhj
w/X8Occ0av1oWnT6JBd6sMCxViMGvBSSNLBCX/ZvNXYXq/+SJM9sjSrCQDdgzIDI
MUt+andCXkFxuQGNBE4J/a0BDADFSeNMstJh2Sx8LlLxTVoBVSPdm2G15kBsikDG
pWN4LiscKQT4Rmzi0uBuA1z+kD+eA+4G2nCqM7xO0RJAPLQi2zcfehdrbdwDBsFb
eCTe2lnbLqGodn0ff7YDlCyopKszgINOQQwXr4VSqG7cOGDGC38taaX5UBR7XJs0
DMb4Hg0Oer7kN3kfSnOwihfS9lgunFIp3dNN1iUEp1NAVOyJhS//4zGh5EYiTd7y
QYQC21H6eiJTmnnvLm/nskiBeR4RFm8ozGAizcji+qwjR1AeeM7ifoIxtuVFH23A
Y7KGzId4y4Bh+Ni8uQO1eTGcc2XITAj5oFdYdC61wJ3B2i1w24gAYNqAJ8bodnYA
JatFRncuaYT6X5bNKHGT+u4KqedR55njEP7XxkXyfL06gI4ri1ef22d8X0kJIY3d
d2LD81qGfAEU8Q/qboPdeaVEtG0FfMCTqQ1yyct1jkbKZMUK/EPompgUZb6JTQov
bRGUPZFbhpq8nVAsu+jRRPVFzmkAEQEAAYkCPAQYAQoAJgIbIBYhBCu70w+qspsy
U7z7pvaUfato57kxBQJqJRqUBQkeFq5nAAoJEPaUfato57kxyy8QAIuF2OHvYFAg
XtIoIQRzOUQBBeBvO0So+15IglJKMiocJWECyklzu0F3mzooA5GsZnXngt11gCUi
Ckrovyty8VNVAPgUc5ZfNYBZ4zhB0rvYMWHOKCkjNRVqExgK3kfgJB9rwrFxyFhI
WAlAW6N5mig/ZWCBe0dz88F/UtjoG20UnHiT+ocVMdbcWj3sUgXqcV44jgXkg/Sn
s2/Riw5fKc1wkAMCyAo+RG4zmMqAlD8Ud/jJRj+kJZY3oGmx/wffsOcb+S9ddxz/
cWmgm5CXtNEORzWmdGuf11gKP+vtne79b1+7WwvA67CqAn3zA1oe+3856fZfJecl
NfI3iohhWe2+DBo2SwimJG1xLbFaSDGYflB1o16g887n/fDVYiUiAvsDk8MUBQun
nhMnVCBjs0+estOWZ+ArXQ/yqiJxsLJip274pi+P5u8qaxuOL9fsZFNEsrkRuAEQ
jiYt3HZOHB0r2Pwg/m6JZ3613gGSNpwayofkZOUlyZvzOJJbxQzXQCJcyRn5QgKs
UMeWR1wKppwywgAgq1sUZkqHPAk98tc/supbC0ltPn63RwcgPqmC9CVm3gw3KELd
51j0+chAOu5zxYEcEHtxxLTpL8MJhdZnCGkuu1hyXxwT5FDY8jmpCSuTu66/73mG
Bu8p/TizH4AvUM3HUiq37bOAdf6Gfco2
=FLNe
-----END PGP PUBLIC KEY BLOCK-----
Learn more about advisories related to aide/aide in the GitHub Advisory Database