Candidate: CVE-2014-9273 PublicDate: 2014-12-08 16:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9273 https://github.com/libguestfs/hivex/commit/357f26fa64fd1d9ccac2331fe174a8ee9c607adb https://github.com/libguestfs/hivex/commit/4bbdf555f88baeae0fa804a369a81a83908bd705 Description: lib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary code and gain privileges via a small hive files, which triggers an out-of-bounds read or write. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_hivex: upstream_hivex: released (1.3.11-1) lucid_hivex: DNE precise_hivex: ignored (reached end-of-life) precise/esm_hivex: DNE (precise was needed) trusty_hivex: ignored (reached end-of-life) trusty/esm_hivex: DNE (trusty was needed) utopic_hivex: ignored (reached end-of-life) vivid_hivex: not-affected (1.3.11-1) vivid/stable-phone-overlay_hivex: DNE vivid/ubuntu-core_hivex: DNE wily_hivex: not-affected (1.3.11-1) xenial_hivex: not-affected (1.3.11-1) yakkety_hivex: not-affected (1.3.11-1) zesty_hivex: not-affected (1.3.11-1) artful_hivex: not-affected (1.3.11-1) bionic_hivex: not-affected (1.3.11-1) cosmic_hivex: not-affected (1.3.11-1) disco_hivex: not-affected (1.3.11-1) devel_hivex: not-affected (1.3.11-1)