Bug 908614 (CVE-2014-9273) - VUL-1: CVE-2014-9273: hivex: Possible DOS because of missing size checks
Summary: VUL-1: CVE-2014-9273: hivex: Possible DOS because of missing size checks
Status: RESOLVED FIXED
Alias: CVE-2014-9273
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.2
: P4 - Low : Minor
Target Milestone: ---
Assignee: Olaf Hering
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/111261/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-12-05 15:47 UTC by Johannes Segitz
Modified: 2015-05-20 09:05 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-12-05 15:47:23 UTC
hivex does not properly handle small-sized hive files and also doesn't
check that pages do not extend beyond the end of the file. 

References:
http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-9273.html
Comment 1 Swamp Workflow Management 2014-12-05 23:00:13 UTC
bugbot adjusting priority
Comment 2 Olaf Hering 2015-01-21 14:57:02 UTC
Maybe I just use ibs mr incorrectly, its all here:

https://build.suse.de/request/show/48872
Comment 3 Olaf Hering 2015-01-22 15:19:22 UTC
https://build.opensuse.org/request/show/282446

Not sure why the webui fails to show changes for 13.2.
Comment 4 Bernhard Wiedemann 2015-01-23 12:00:07 UTC
This is an autogenerated message for OBS integration:
This bug (908614) was mentioned in
https://build.opensuse.org/request/show/282538 13.2+13.1 / hivex
Comment 6 Swamp Workflow Management 2015-02-02 09:09:58 UTC
openSUSE-SU-2015:0189-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 908614
CVE References: CVE-2014-9273
Sources used:
openSUSE 13.2 (src):    hivex-1.3.10-2.4.1
openSUSE 13.1 (src):    hivex-1.3.8-2.4.1
Comment 7 Swamp Workflow Management 2015-02-18 16:06:06 UTC
SUSE-SU-2015:0320-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 908614
CVE References: CVE-2014-9273
Sources used:
SUSE Linux Enterprise Software Development Kit 12 (src):    hivex-1.3.10-4.1
SUSE Linux Enterprise Server 12 (src):    hivex-1.3.10-4.1
Comment 8 Olaf Hering 2015-03-17 09:29:16 UTC
I think this can be closed now?
Comment 9 Olaf Hering 2015-05-20 09:05:52 UTC
Closing as "fix released"