In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial of service and even code execution.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://ntfs-3g.com | product vendor advisory |
http://www.openwall.com/lists/oss-security/2021/08/30/1 | third party advisory mailing list |
https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-q759-8j5v-q5jp | third party advisory |
https://www.debian.org/security/2021/dsa-4971 | third party advisory vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/766ISTT3KCARKFUIQT7N6WV6T63XOKG3/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSEKTKHO5HFZHWZNJNBJZA56472KRUZI/ | vendor advisory |
https://lists.debian.org/debian-lts-announce/2021/11/msg00013.html | third party advisory mailing list |
https://security.gentoo.org/glsa/202301-01 | third party advisory vendor advisory |