cbcvebase.
CVE-2021-3622
published 2021-12-23

CVE-2021-3622: A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to…

medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianhivex< hivex 1.3.21-1 (bookworm)hivex 1.3.21-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_hivex_1.3.21-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_workstation
redhathivex< 1.3.211.3.21
redhathivex
redhathivex>= 0 < 1.3.21-11.3.21-1
redhathivex>= 0 < 1.3.21-11.3.21-1
redhathivex>= 0 < 1.3.21-11.3.21-1

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
osv4.3MEDIUM