Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mxp6-gc8g-j2p9

Опубликовано: 04 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes.

This may permit a user with write access to files on a msdosfs filesystem to read unintended data (e.g. from a previously deleted file).

On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes.

This may permit a user with write access to files on a msdosfs filesystem to read unintended data (e.g. from a previously deleted file).

EPSS

Процентиль: 34%
0.00134
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1188

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes. This may permit a user with write access to files on a msdosfs filesystem to read unintended data (e.g. from a previously deleted file).

EPSS

Процентиль: 34%
0.00134
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1188