========================================================================== Ubuntu Security Notice USN-5148-1 November 16, 2021 hivex vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 21.04 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: hivex could be made to crash or leak information if it received specially crafted input. Software Description: - hivex: utilities for reading and writing Windows Registry hives Details: It was discovered that hivex incorrectly handled certain input. An attacker could use this vulnerability to cause a crash or obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: libhivex-bin 1.3.19-1ubuntu3.21.10.1 libhivex0 1.3.19-1ubuntu3.21.10.1 Ubuntu 21.04: libhivex-bin 1.3.19-1ubuntu3.21.04.1 libhivex0 1.3.19-1ubuntu3.21.04.1 Ubuntu 20.04 LTS: libhivex-bin 1.3.18-2ubuntu0.1 libhivex0 1.3.18-2ubuntu0.1 Ubuntu 18.04 LTS: libhivex-bin 1.3.15-1ubuntu0.1 libhivex0 1.3.15-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5148-1 CVE-2021-3504 Package Information: https://launchpad.net/ubuntu/+source/hivex/1.3.19-1ubuntu3.21.10.1 https://launchpad.net/ubuntu/+source/hivex/1.3.19-1ubuntu3.21.04.1 https://launchpad.net/ubuntu/+source/hivex/1.3.18-2ubuntu0.1 https://launchpad.net/ubuntu/+source/hivex/1.3.15-1ubuntu0.1