CVE-2021-3504 is a medium-severity vulnerability affecting the hivex library (versions prior to 1.3.20) in Debian, Fedora, and Red Hat products. This flaw, a lack of bounds checking in the hivex_open function, allows an unauthenticated attacker to cause a denial of service or information disclosure by tricking a user into opening a specially crafted Windows Registry file. While the vulnerability is not actively exploited, has no public exploit code, and minimal community discussion, its potential impact on system availability warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.20CPE matchmatch criteria | cpe:2.3:a:redhat:hivex:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2021-3504
Dec 14, 2021A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability.
May 11, 2021hivex: Buffer overflow when provided invalid node key length
May 3, 2021