Stack-based buffer overflow in hivex - CVE-2021-3622

 

Stack-based buffer overflow in hivex - CVE-2021-3622

Published: September 1, 2021


Vulnerability identifier: #VU56239
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3622
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing hive child objects. A local user can create a specially crafted Windows Registry (hive) file which would cause hivex to recursively call the _get_children() function, ultimately leading to a stack overflow and library crash.


Affected software

hivex
hivex (Red Hat package)
perl-Win-Hivex-debuginfo
perl-Win-Hivex
libhivex0-debuginfo
hivex-debuginfo
hivex-debugsource
hivex-devel
libhivex0
ocaml-hivex-devel
ocaml-hivex-debuginfo
ocaml-hivex
hivex-help
python3-hivex
perl-hivex
python2-hivex
ruby-hivex
hivex
SUSE MicroOS
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
CentOS
Red Hat Enterprise Linux Server
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora

How to mitigate CVE-2021-3622

Install updates from vendor's website.

hivex - update to 1.3.21
hivex (Red Hat package) - update to 1.3.10-6.12.el7_9
perl-Win-Hivex-debuginfo - addressed in versions 1.3.10-5.7.1, 1.3.14-5.6.1
perl-Win-Hivex - addressed in versions 1.3.10-5.7.1, 1.3.14-5.6.1
libhivex0-debuginfo - addressed in versions 1.3.10-5.7.1, 1.3.14-5.6.1
hivex-debuginfo - addressed in versions 1.3.10-5.7.1, 1.3.14-5.6.1
hivex-debugsource - addressed in versions 1.3.10-5.7.1, 1.3.14-5.6.1
hivex-devel - addressed in versions 1.3.10-5.7.1, 1.3.14-5.6.1
libhivex0 - addressed in versions 1.3.10-5.7.1, 1.3.14-5.6.1
ocaml-hivex-devel - update to 1.3.14-5.6.1
ocaml-hivex-debuginfo - update to 1.3.14-5.6.1
ocaml-hivex - update to 1.3.14-5.6.1
ocaml-hivex - update to 1.3.17-4
hivex-help - update to 1.3.17-4
python3-hivex - update to 1.3.17-4
hivex-devel - update to 1.3.17-4
hivex-debuginfo - update to 1.3.17-4
perl-hivex - update to 1.3.17-4
python2-hivex - update to 1.3.17-4
hivex-debugsource - update to 1.3.17-4
ocaml-hivex-devel - update to 1.3.17-4
ruby-hivex - update to 1.3.17-4
hivex - update to 1.3.17-4
hivex - addressed in versions 1.3.21-1.fc33, 1.3.21-1.fc34

External References

Related Security Bulletins