CVE-2021-3504
published 2021-05-11CVE-2021-3504: A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could…
PriorityP427medium5.4CVSS 3.1
AVNACLPRNUIRSUCLINAL
EPSS
1.92%
77.5th percentile
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | hivex | < hivex 1.3.20-1 (bookworm) | hivex 1.3.20-1 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | cbl2_hivex_1.3.21-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | hivex | < 1.3.20 | 1.3.20 |
| redhat | hivex | — | — |
| redhat | hivex | >= 0 < 1.3.20-1 | 1.3.20-1 |
| redhat | hivex | >= 0 < 1.3.20-1 | 1.3.20-1 |
| redhat | hivex | >= 0 < 1.3.20-1 | 1.3.20-1 |
| redhat | hivex | >= 0 < 1.3.20-1 | 1.3.20-1 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_msrc5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
hivex vulnerability
vendor_ubuntu·2021-11-16
CVE-2021-3504 hivex vulnerability
Title: hivex vulnerability
Summary: hivex could be made to crash or leak information if it received specially
crafted input.
It was discovered that hivex incorrectly handled certain input. An attacker
could use this vulnerability to cause a crash or obtain sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
hivex vulnerability
vendor_ubuntu·2021-11-16
CVE-2021-3504 hivex vulnerability
Title: hivex vulnerability
Summary: hivex could be made to crash or leak information if it received specially
crafted input.
USN-5148-1 fixed a vulnerability in hivex. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that hivex incorrectly handled certain input. An attacker
could use this vulnerability to cause a crash or obtain sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry
vendor_msrc·2021-05-11·CVSS 5.4
CVE-2021-3504 [MEDIUM] CWE-125 A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in
Red Hat
hivex: Buffer overflow when provided invalid node key length
vendor_redhat·2021-05-03·CVSS 5.4
CVE-2021-3504 [MEDIUM] CWE-125 hivex: Buffer overflow when provided invalid node key length
hivex: Buffer overflow when provided invalid node key length
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability.
A flaw was found in the hivex library. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability.
Statem
Debian
CVE-2021-3504: hivex - A flaw was found in the hivex library in versions before 1.3.20. It is caused du...
vendor_debian·2021·CVSS 5.4
CVE-2021-3504 [MEDIUM] CVE-2021-3504: hivex - A flaw was found in the hivex library in versions before 1.3.20. It is caused du...
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 1.3.20-1)
bullseye: resolved (fixed in 1.3.20-1)
forky: resolved (fixed in 1.3.20-1)
sid: resolved (fixed in 1.3.20-1)
trixie: resolved (fixed in 1.3.20-1)
GHSA
GHSA-5vp3-c6x6-5464: A flaw was found in the hivex library in versions before 1
ghsa_unreviewed·2022-05-24
CVE-2021-3504 [HIGH] CWE-125 GHSA-5vp3-c6x6-5464: A flaw was found in the hivex library in versions before 1
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability.
OSV
CVE-2021-3504: A flaw was found in the hivex library in versions before 1
osv·2021-05-11·CVSS 5.4
CVE-2021-3504 [MEDIUM] CVE-2021-3504: A flaw was found in the hivex library in versions before 1
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1949687https://lists.debian.org/debian-lts-announce/2021/05/msg00011.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5BNKNVYFL36P2GBEB5O36LHFRYU575H/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQXTEACRWYAZVNEOIWIYUFGG4GOXSQ22/https://bugzilla.redhat.com/show_bug.cgi?id=1949687https://lists.debian.org/debian-lts-announce/2021/05/msg00011.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5BNKNVYFL36P2GBEB5O36LHFRYU575H/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQXTEACRWYAZVNEOIWIYUFGG4GOXSQ22/
2021-05-11
Published