Out-of-bounds read in hivex - CVE-2021-3504
Published: June 15, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the hivex_open() function when processing a Windows Registry (hive) file. A remote attacker can create a specially crafted Windows Registry (hive) file, trick the victim into opening it, trigger out-of-bounds read error and crash the application that us using the affected library.
Affected software
Arch Linux
Debian Linux
SUSE MicroOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
CentOS
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
hivex-debuginfo
hivex-debugsource
hivex-devel
libhivex0
libhivex0-debuginfo
perl-Win-Hivex
perl-Win-Hivex-debuginfo
hivex (Red Hat package)
ocaml-hivex-devel
ocaml-hivex-debuginfo
ocaml-hivex
libhivex-bin (Ubuntu package)
libhivex0 (Ubuntu package)
python2-hivex
python3-hivex
hivex
perl-hivex
ruby-hivex
hivex-help
hivex (Debian package)
How to mitigate CVE-2021-3504
hivex-debuginfo - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
hivex-debugsource - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
hivex-devel - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
libhivex0 - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
libhivex0-debuginfo - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
perl-Win-Hivex - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
perl-Win-Hivex-debuginfo - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
hivex (Red Hat package) - update to 1.3.10-6.11.el7_9
ocaml-hivex-devel - update to 1.3.14-5.3.1
ocaml-hivex-debuginfo - update to 1.3.14-5.3.1
ocaml-hivex - update to 1.3.14-5.3.1
libhivex-bin (Ubuntu package) - addressed in versions 1.3.15-1ubuntu0.1, 1.3.18-2ubuntu0.1, 1.3.19-1ubuntu3.21.04.1, 1.3.19-1ubuntu3.21.10.1
libhivex0 (Ubuntu package) - addressed in versions 1.3.15-1ubuntu0.1, 1.3.18-2ubuntu0.1, 1.3.19-1ubuntu3.21.04.1, 1.3.19-1ubuntu3.21.10.1
python2-hivex - update to 1.3.17-3
hivex-debuginfo - update to 1.3.17-3
ocaml-hivex-devel - update to 1.3.17-3
python3-hivex - update to 1.3.17-3
hivex - update to 1.3.17-3
perl-hivex - update to 1.3.17-3
ocaml-hivex - update to 1.3.17-3
hivex-debugsource - update to 1.3.17-3
hivex-devel - update to 1.3.17-3
ruby-hivex - update to 1.3.17-3
hivex-help - update to 1.3.17-3
hivex (Debian package) - update to 1.3.18-1+deb10u1
hivex - update to 1.3.20-1
hivex - addressed in versions 1.3.20-1.fc33, 1.3.20-1.fc34
External References
- https://bugzilla.redhat.com/show_bug.cgi?id=1949687
- https://lists.debian.org/debian-lts-announce/2021/05/msg00011.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BQXTEACRWYAZVNEOIWIYUFGG4GOXSQ22/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A5BNKNVYFL36P2GBEB5O36LHFRYU575H/
Related Security Bulletins
- Denial of service in hivex library
- CentOS 7 update for hivex
- Red Hat Enterprise Linux 7 update for hivex
- SUSE update for hivex
- SUSE update for hivex
- Ubuntu update for hivex
- Debian update for hivex
- Arch Linux update for hivex
- openEuler 20.03 LTS SP1 update for hivex
- Fedora 34 update for hivex
- Fedora 33 update for hivex