hivex: User-assisted execution of arbitrary code — GLSA 201503-07

An out-of-bounds error in hivex may result in execution of arbitrary code or Denial of Service.

Affected Packages

app-misc/hivex on all architectures
Affected versions < 1.3.11
Unaffected versions >= 1.3.11

Background

hivex is a library for reading and writing Windows Registry ‘hive’ binary files.

Description

Manipulating a short or truncated hive file may trigger an out-of-bounds read or write in hivex.

Impact

A context-dependent attacker could cause an application linked against hivex to pass a short or truncated hive file, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition.

Workaround

There is no known workaround at this time.

Resolution

All hivex users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=app-misc/hivex-1.3.11"
 

References

Release Date
March 14, 2015

Latest Revision
March 14, 2015: 1

Severity
normal

Exploitable
local, remote

Bugzilla entries