Hivex 'lib/handle.c' Remote Code Execution Vulnerability
BID:71279
Info
Hivex 'lib/handle.c' Remote Code Execution Vulnerability
| Bugtraq ID: | 71279 |
| Class: | Unknown |
| CVE: |
CVE-2014-9273 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 29 2014 12:00AM |
| Updated: | Nov 03 2015 07:22PM |
| Credit: | Mahmoud Al-Qudsi of NeoSmart Technologies. |
| Vulnerable: |
Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Hivex 'lib/handle.c' Remote Code Execution Vulnerability
Hivex is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
Hivex 1.3.0 is vulnerable; other versions may also be affected.
Hivex is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
Hivex 1.3.0 is vulnerable; other versions may also be affected.
Exploit / POC
Hivex 'lib/handle.c' Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Hivex 'lib/handle.c' Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Hivex 'lib/handle.c' Remote Code Execution Vulnerability
References:
References:
- [Libguestfs] [libhivex] Undefined behavior when accessing invalid (too small) re (Red Hat)
- Bug 1167756 - hivex: missing checks for small-sized files (Red Hat Bugzilla)
- handle: Check that pages do not extend beyond the end of the file. (Red Hat)
- handle: Refuse to open files < 8192 bytes in size. (Red Hat)
- Hivex Home Page (Red Hat)
- Security Bulletin: Multiple vulnerabilities in NTP, Hivex, glibc, libuser, BIND (IBM)