Bug#988024: hivex: CVE-2021-3504

2021-05-05 Thread Salvatore Bonaccorso
Hi Hilko On Wed, May 05, 2021 at 12:06:09AM +0200, Hilko Bengen wrote: > * Salvatore Bonaccorso: > > > CVE-2021-3504[0]: > > | Buffer overflow when provided invalid node key length > > > > Making the severity RC as I think the fix needs to go into bullseye. > > Right. > > I contacted team@secur

Bug#988024: hivex: CVE-2021-3504

2021-05-04 Thread Hilko Bengen
* Salvatore Bonaccorso: > CVE-2021-3504[0]: > | Buffer overflow when provided invalid node key length > > Making the severity RC as I think the fix needs to go into bullseye. Right. I contacted team@security.d.o a about the issue, including a proposed hivex/1.3.18-1+deb10u1 for stable-security a

Bug#988024: hivex: CVE-2021-3504

2021-05-03 Thread Salvatore Bonaccorso
Source: hivex Version: 1.3.19-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for hivex. CVE-2021-3504[0]: | Buffer overflow when provided invalid node key length Mak