Bug 1949687 (CVE-2021-3504)
Summary: | CVE-2021-3504 hivex: Buffer overflow when provided invalid node key length | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | gkamathe, rjones, security-response-team, virt-maint |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | hivex-1.3.20 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in the hivex library. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2021-06-01 07:35:22 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1950500, 1950501, 1950917, 1952988, 1956204, 1957103 | ||
Bug Blocks: | 1949688, 1950347 |
Description
Pedro Sampaio
2021-04-14 19:48:38 UTC
Statement: This flaw affects all previous hivex versions up to version 1.3.19 Created hivex tracking bugs for this issue: Affects: fedora-all [bug 1956204] Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2021:2318 https://access.redhat.com/errata/RHSA-2021:2318 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:3061 https://access.redhat.com/errata/RHSA-2021:3061 |