In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://ntfs-3g.com | product |
http://tuxera.com | product |
http://www.openwall.com/lists/oss-security/2021/08/30/1 | third party advisory mailing list |
https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-q759-8j5v-q5jp | third party advisory |
https://www.debian.org/security/2021/dsa-4971 | third party advisory vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/766ISTT3KCARKFUIQT7N6WV6T63XOKG3/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSEKTKHO5HFZHWZNJNBJZA56472KRUZI/ | vendor advisory |
https://lists.debian.org/debian-lts-announce/2021/11/msg00013.html | third party advisory mailing list |
https://security.gentoo.org/glsa/202301-01 | third party advisory vendor advisory |