Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-3622
HistoryDec 23, 2021 - 12:00 a.m.

CVE-2021-3622

2021-12-2300:00:00
ubuntu.com
ubuntu.com
10
hivex library
stack overflow
windows registry

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

EPSS

0.002

Percentile

64.8%

A flaw was found in the hivex library. This flaw allows an attacker to
input a specially crafted Windows Registry (hive) file, which would cause
hivex to recursively call the _get_children() function, leading to a stack
overflow. The highest threat from this vulnerability is to system
availability.

Bugs

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

EPSS

0.002

Percentile

64.8%