ALAS2-2021-1658

Related Vulnerabilities: CVE-2021-3504  

A flaw was found in the hivex library. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability. (CVE-2021-3504)

ALAS2-2021-1658


Amazon Linux 2 Security Advisory: ALAS-2021-1658
Advisory Release Date: 2021-06-16 20:37 Pacific
Advisory Updated Date: 2021-06-22 22:09 Pacific
Severity: Medium
References: CVE-2021-3504 

Issue Overview:

A flaw was found in the hivex library. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability. (CVE-2021-3504)


Affected Packages:

hivex


Issue Correction:
Run yum update hivex to update your system.

New Packages:
aarch64:
    hivex-1.3.10-6.11.amzn2.aarch64
    hivex-devel-1.3.10-6.11.amzn2.aarch64
    ocaml-hivex-1.3.10-6.11.amzn2.aarch64
    ocaml-hivex-devel-1.3.10-6.11.amzn2.aarch64
    perl-hivex-1.3.10-6.11.amzn2.aarch64
    python-hivex-1.3.10-6.11.amzn2.aarch64
    ruby-hivex-1.3.10-6.11.amzn2.aarch64
    hivex-debuginfo-1.3.10-6.11.amzn2.aarch64

i686:
    hivex-1.3.10-6.11.amzn2.i686
    hivex-devel-1.3.10-6.11.amzn2.i686
    ocaml-hivex-1.3.10-6.11.amzn2.i686
    ocaml-hivex-devel-1.3.10-6.11.amzn2.i686
    perl-hivex-1.3.10-6.11.amzn2.i686
    python-hivex-1.3.10-6.11.amzn2.i686
    ruby-hivex-1.3.10-6.11.amzn2.i686
    hivex-debuginfo-1.3.10-6.11.amzn2.i686

src:
    hivex-1.3.10-6.11.amzn2.src

x86_64:
    hivex-1.3.10-6.11.amzn2.x86_64
    hivex-devel-1.3.10-6.11.amzn2.x86_64
    ocaml-hivex-1.3.10-6.11.amzn2.x86_64
    ocaml-hivex-devel-1.3.10-6.11.amzn2.x86_64
    perl-hivex-1.3.10-6.11.amzn2.x86_64
    python-hivex-1.3.10-6.11.amzn2.x86_64
    ruby-hivex-1.3.10-6.11.amzn2.x86_64
    hivex-debuginfo-1.3.10-6.11.amzn2.x86_64