Out-of-bounds read in hivex - CVE-2021-3504

 

Out-of-bounds read in hivex - CVE-2021-3504

Published: June 15, 2021


Vulnerability identifier: #VU54109
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3504
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the hivex_open() function when processing a Windows Registry (hive) file. A remote attacker can create a specially crafted Windows Registry (hive) file, trick the victim into opening it, trigger out-of-bounds read error and crash the application that us using the affected library.


Affected software

hivex
Arch Linux
Debian Linux
SUSE MicroOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
CentOS
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
hivex-debuginfo
hivex-debugsource
hivex-devel
libhivex0
libhivex0-debuginfo
perl-Win-Hivex
perl-Win-Hivex-debuginfo
hivex (Red Hat package)
ocaml-hivex-devel
ocaml-hivex-debuginfo
ocaml-hivex
libhivex-bin (Ubuntu package)
libhivex0 (Ubuntu package)
python2-hivex
python3-hivex
hivex
perl-hivex
ruby-hivex
hivex-help
hivex (Debian package)

How to mitigate CVE-2021-3504

Install updates from vendor's website.

hivex - update to 1.3.20
hivex-debuginfo - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
hivex-debugsource - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
hivex-devel - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
libhivex0 - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
libhivex0-debuginfo - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
perl-Win-Hivex - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
perl-Win-Hivex-debuginfo - addressed in versions 1.3.10-5.3.1, 1.3.14-5.3.1
hivex (Red Hat package) - update to 1.3.10-6.11.el7_9
ocaml-hivex-devel - update to 1.3.14-5.3.1
ocaml-hivex-debuginfo - update to 1.3.14-5.3.1
ocaml-hivex - update to 1.3.14-5.3.1
libhivex-bin (Ubuntu package) - addressed in versions 1.3.15-1ubuntu0.1, 1.3.18-2ubuntu0.1, 1.3.19-1ubuntu3.21.04.1, 1.3.19-1ubuntu3.21.10.1
libhivex0 (Ubuntu package) - addressed in versions 1.3.15-1ubuntu0.1, 1.3.18-2ubuntu0.1, 1.3.19-1ubuntu3.21.04.1, 1.3.19-1ubuntu3.21.10.1
python2-hivex - update to 1.3.17-3
hivex-debuginfo - update to 1.3.17-3
ocaml-hivex-devel - update to 1.3.17-3
python3-hivex - update to 1.3.17-3
hivex - update to 1.3.17-3
perl-hivex - update to 1.3.17-3
ocaml-hivex - update to 1.3.17-3
hivex-debugsource - update to 1.3.17-3
hivex-devel - update to 1.3.17-3
ruby-hivex - update to 1.3.17-3
hivex-help - update to 1.3.17-3
hivex (Debian package) - update to 1.3.18-1+deb10u1
hivex - update to 1.3.20-1
hivex - addressed in versions 1.3.20-1.fc33, 1.3.20-1.fc34

External References

Related Security Bulletins