Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-11730

Опубликовано: 19 июн. 2018
Источник: debian
EPSS Низкий

Описание

The libfsntfs_security_descriptor_values_free function in libfsntfs_security_descriptor_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause a denial of service (double-free) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libfsntfsfixed20190104-1package

Примечания

  • http://seclists.org/fulldisclosure/2018/Jun/17

  • https://github.com/libyal/libfsntfs/issues/8

  • https://github.com/libyal/libfsntfs/issues/9

  • https://github.com/libyal/libfsntfs/commit/7a17c43be39919227b4fe24684a8a29a90ee54ad

  • Negligable/questionable security impact

EPSS

Процентиль: 37%
0.00158
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

The libfsntfs_security_descriptor_values_free function in libfsntfs_security_descriptor_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause a denial of service (double-free) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub

CVSS3: 5.5
nvd
больше 7 лет назад

The libfsntfs_security_descriptor_values_free function in libfsntfs_security_descriptor_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause a denial of service (double-free) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub

CVSS3: 5.5
github
больше 3 лет назад

** DISPUTED ** The libfsntfs_security_descriptor_values_free function in libfsntfs_security_descriptor_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause a denial of service (double-free) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub.

EPSS

Процентиль: 37%
0.00158
Низкий