Heap-based buffer overflow in NTFS-3G - CVE-2019-9755

 

Heap-based buffer overflow in NTFS-3G - CVE-2019-9755

Published: April 19, 2019


Vulnerability identifier: #VU18324
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9755
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the target system.

The vulnerability exists due to a boundary error when executing the NTFS-3G driver with an overly long relative mount point path. A local usre can create directory structure with specially crafted names, trigger heap-based buffer overflow and execute arbitrary code on the target system with elevated privileges.



Affected software

NTFS-3G
Gentoo Linux
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Opensuse
openEuler
Red Hat Virtualization
ntfs-3g (Ubuntu package)
ntfs-3g (Debian package)
ntfs-3g (Alpine package)
ntfs-3g
ntfs-3g-devel
ntfs-3g-debugsource
ntfs-3g-debuginfo
ntfs-3g-help

How to mitigate CVE-2019-9755

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

ntfs-3g (Ubuntu package) - addressed in versions 1:2015.3.14AR.1-1ubuntu0.2, 1:2015.3.14AR.1-1ubuntu0.3, 1:2017.3.23-2ubuntu0.18.04.1, 1:2017.3.23-2ubuntu0.18.04.2, 1:2017.3.23-2ubuntu0.18.10.1, 1:2017.3.23-2ubuntu0.18.10.2
ntfs-3g (Debian package) - update to 1:2016.2.22AR.1+dfsg-1+deb9u1
ntfs-3g (Alpine package) - update to 2017.3.23-r2
ntfs-3g - update to 2017.3.23-11
ntfs-3g-devel - update to 2017.3.23-11
ntfs-3g-debugsource - update to 2017.3.23-11
ntfs-3g-debuginfo - update to 2017.3.23-11
ntfs-3g-help - update to 2017.3.23-11
ntfs-3g - addressed in versions 2017.3.23-11.el6, 2017.3.23-11.el7, 2017.3.23-11.fc28, 2017.3.23-11.fc29, 2017.3.23-11.fc30

External References

Related Security Bulletins