Bugzilla – Bug 908614
VUL-1: CVE-2014-9273: hivex: Possible DOS because of missing size checks
Last modified: 2015-05-20 09:05:52 UTC
hivex does not properly handle small-sized hive files and also doesn't check that pages do not extend beyond the end of the file. References: http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-9273.html
bugbot adjusting priority
Maybe I just use ibs mr incorrectly, its all here: https://build.suse.de/request/show/48872
https://build.opensuse.org/request/show/282446 Not sure why the webui fails to show changes for 13.2.
This is an autogenerated message for OBS integration: This bug (908614) was mentioned in https://build.opensuse.org/request/show/282538 13.2+13.1 / hivex
openSUSE-SU-2015:0189-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 908614 CVE References: CVE-2014-9273 Sources used: openSUSE 13.2 (src): hivex-1.3.10-2.4.1 openSUSE 13.1 (src): hivex-1.3.8-2.4.1
SUSE-SU-2015:0320-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 908614 CVE References: CVE-2014-9273 Sources used: SUSE Linux Enterprise Software Development Kit 12 (src): hivex-1.3.10-4.1 SUSE Linux Enterprise Server 12 (src): hivex-1.3.10-4.1
I think this can be closed now?
Closing as "fix released"