SB2021093029 - openEuler update for hivex
Published: September 30, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Stack-based buffer overflow (CVE-ID: CVE-2021-3622)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing hive child objects. A local user can create a specially crafted Windows Registry (hive) file which would cause hivex to recursively call the _get_children() function, ultimately leading to a stack overflow and library crash.
Remediation
Install update from vendor's website.