ALAS2-2021-1717

Related Vulnerabilities: CVE-2021-3622  

A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability. (CVE-2021-3622)

ALAS2-2021-1717


Amazon Linux 2 Security Advisory: ALAS-2021-1717
Advisory Release Date: 2021-10-28 23:19 Pacific
Advisory Updated Date: 2021-11-04 18:03 Pacific
Severity: Low
References: CVE-2021-3622 

Issue Overview:

A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability. (CVE-2021-3622)


Affected Packages:

hivex


Issue Correction:
Run yum update hivex to update your system.

New Packages:
aarch64:
    hivex-1.3.10-6.12.amzn2.aarch64
    hivex-devel-1.3.10-6.12.amzn2.aarch64
    ocaml-hivex-1.3.10-6.12.amzn2.aarch64
    ocaml-hivex-devel-1.3.10-6.12.amzn2.aarch64
    perl-hivex-1.3.10-6.12.amzn2.aarch64
    python-hivex-1.3.10-6.12.amzn2.aarch64
    ruby-hivex-1.3.10-6.12.amzn2.aarch64
    hivex-debuginfo-1.3.10-6.12.amzn2.aarch64

i686:
    hivex-1.3.10-6.12.amzn2.i686
    hivex-devel-1.3.10-6.12.amzn2.i686
    ocaml-hivex-1.3.10-6.12.amzn2.i686
    ocaml-hivex-devel-1.3.10-6.12.amzn2.i686
    perl-hivex-1.3.10-6.12.amzn2.i686
    python-hivex-1.3.10-6.12.amzn2.i686
    ruby-hivex-1.3.10-6.12.amzn2.i686
    hivex-debuginfo-1.3.10-6.12.amzn2.i686

src:
    hivex-1.3.10-6.12.amzn2.src

x86_64:
    hivex-1.3.10-6.12.amzn2.x86_64
    hivex-devel-1.3.10-6.12.amzn2.x86_64
    ocaml-hivex-1.3.10-6.12.amzn2.x86_64
    ocaml-hivex-devel-1.3.10-6.12.amzn2.x86_64
    perl-hivex-1.3.10-6.12.amzn2.x86_64
    python-hivex-1.3.10-6.12.amzn2.x86_64
    ruby-hivex-1.3.10-6.12.amzn2.x86_64
    hivex-debuginfo-1.3.10-6.12.amzn2.x86_64