=========================================================================Ubuntu Security Notice USN-5148-1
November 16, 2021

hivex vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.10
- Ubuntu 21.04
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

hivex could be made to crash or leak information if it received specially
crafted input.

Software Description:
- hivex: utilities for reading and writing Windows Registry hives

Details:

It was discovered that hivex incorrectly handled certain input. An attacker
could use this vulnerability to cause a crash or obtain sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.10:
  libhivex-bin                    1.3.19-1ubuntu3.21.10.1
  libhivex0                       1.3.19-1ubuntu3.21.10.1

Ubuntu 21.04:
  libhivex-bin                    1.3.19-1ubuntu3.21.04.1
  libhivex0                       1.3.19-1ubuntu3.21.04.1

Ubuntu 20.04 LTS:
  libhivex-bin                    1.3.18-2ubuntu0.1
  libhivex0                       1.3.18-2ubuntu0.1

Ubuntu 18.04 LTS:
  libhivex-bin                    1.3.15-1ubuntu0.1
  libhivex0                       1.3.15-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5148-1
  CVE-2021-3504

Package Information:
  https://launchpad.net/ubuntu/+source/hivex/1.3.19-1ubuntu3.21.10.1
  https://launchpad.net/ubuntu/+source/hivex/1.3.19-1ubuntu3.21.04.1
  https://launchpad.net/ubuntu/+source/hivex/1.3.18-2ubuntu0.1
  https://launchpad.net/ubuntu/+source/hivex/1.3.15-1ubuntu0.1

Ubuntu 5148-1: hivex vulnerability

November 16, 2021
hivex could be made to crash or leak information if it received specially crafted input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: libhivex-bin 1.3.19-1ubuntu3.21.10.1 libhivex0 1.3.19-1ubuntu3.21.10.1 Ubuntu 21.04: libhivex-bin 1.3.19-1ubuntu3.21.04.1 libhivex0 1.3.19-1ubuntu3.21.04.1 Ubuntu 20.04 LTS: libhivex-bin 1.3.18-2ubuntu0.1 libhivex0 1.3.18-2ubuntu0.1 Ubuntu 18.04 LTS: libhivex-bin 1.3.15-1ubuntu0.1 libhivex0 1.3.15-1ubuntu0.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5148-1

CVE-2021-3504

Severity
November 16, 2021

Package Information

https://launchpad.net/ubuntu/+source/hivex/1.3.19-1ubuntu3.21.10.1 https://launchpad.net/ubuntu/+source/hivex/1.3.19-1ubuntu3.21.04.1 https://launchpad.net/ubuntu/+source/hivex/1.3.18-2ubuntu0.1 https://launchpad.net/ubuntu/+source/hivex/1.3.15-1ubuntu0.1

Related News