Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-46790

Опубликовано: 25 нояб. 2021
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.

A vulnerability was found in NTFS-3G, specifically in the ntfsck utility. Incorrect validation of NTFS metadata can result in a heap-based buffer overflow when processing a crafted NTFS image file or partition.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libguestfs-winsupportOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/libguestfs-winsupportWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libguestfs-winsupportWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt-devel:8.2/libguestfs-winsupportWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt-devel:av/libguestfs-winsupportWill not fix
Red Hat Enterprise Linux 8virt-develFixedRHSA-2023:275716.05.2023
Red Hat Enterprise Linux 8virtFixedRHSA-2023:275716.05.2023
Red Hat Enterprise Linux 9libguestfs-winsupportFixedRHSA-2023:217909.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2093358ntfs-3g: heap-based buffer overflow in ntfsck

EPSS

Процентиль: 10%
0.00037
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 3 лет назад

ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.

CVSS3: 7.8
nvd
около 3 лет назад

ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.

CVSS3: 7.8
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 7.8
debian
около 3 лет назад

ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow i ...

CVSS3: 9.8
github
около 3 лет назад

ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.

EPSS

Процентиль: 10%
0.00037
Низкий

7.8 High

CVSS3