SB2022060818 - Multiple vulnerabilities in Tuxera NTFS-3G
Published: June 8, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Heap-based buffer overflow (CVE-ID: CVE-2022-30789)
The vulnerability allows a local attacker to execute arbitrary code with escalated privileges.
The vulnerability exists due to a boundary error in the ntfs_check_log_client_array in NTFS-3G. A local attacker can mount a specially crafted NTFS image, trigger a heap-based buffer overflow and execute arbitrary code with escalated privileges.
2) Heap-based buffer overflow (CVE-ID: CVE-2021-46790)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error in the ntfsck in NTFS-3G when processing specially crafted NTFS filesystem. A local user can mount a malicious NTFS filesystem, trigger a heap-based buffer overflow and execute arbitrary code with elevated privileges.
Remediation
Install update from vendor's website.
References
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4x
- https://github.com/tuxera/ntfs-3g/releases
- https://bugzilla.redhat.com/show_bug.cgi?id=2093348
- https://github.com/tuxera/ntfs-3g/issues/16
- http://www.openwall.com/lists/oss-security/2022/05/26/1
- https://bugzilla.redhat.com/show_bug.cgi?id=2093358