Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3622

Опубликовано: 02 авг. 2021
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.

Отчет

Any external program using the hivex library could be exposed to partial unavailability in case of a crash where a user can always retry the operation. As for libguestfs, a crash in hivex would not result in libguestfs crashing.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6hivexOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/hivexWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/hivexWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/hivexAffected
Red Hat Enterprise Linux 9hivexNot affected
Red Hat Enterprise Linux 7hivexFixedRHSA-2021:333831.08.2021
Red Hat Enterprise Linux 8virt-develFixedRHSA-2022:175910.05.2022
Red Hat Enterprise Linux 8virtFixedRHSA-2022:175910.05.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1975489hivex: stack overflow due to recursive call of _get_children()

EPSS

Процентиль: 68%
0.00583
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 3 лет назад

A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.

CVSS3: 4.3
nvd
больше 3 лет назад

A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.

CVSS3: 4.3
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 4.3
debian
больше 3 лет назад

A flaw was found in the hivex library. This flaw allows an attacker to ...

suse-cvrf
больше 3 лет назад

Security update for hivex

EPSS

Процентиль: 68%
0.00583
Низкий

4.3 Medium

CVSS3