Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-30785

Опубликовано: 26 мая 2022
Источник: redhat
CVSS3: 6.7

Описание

A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

A vulnerability was found in NTFS-3G. A file handle created in fuse_lib_opendir and later used in fuse_lib_readdir allows out-of-bounds read/write operations.

Отчет

The package libguestfs-winsupport, as shipped with Red Hat Enterprise Linux, is not affected by this vulnerability as it does not use the internal libfuse, known as libfuse-lite or libfuse2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libguestfs-winsupportOut of support scope
Red Hat Enterprise Linux 8virt:rhel/libguestfs-winsupportNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/libguestfs-winsupportNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libguestfs-winsupportNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt-devel:8.2/libguestfs-winsupportNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt-devel:av/libguestfs-winsupportNot affected
Red Hat Enterprise Linux 9libguestfs-winsupportNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2093320ntfs-3g: a file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 3 лет назад

A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVSS3: 6.7
nvd
около 3 лет назад

A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVSS3: 6.7
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 6.7
debian
около 3 лет назад

A file handle created in fuse_lib_opendir, and later used in fuse_lib_ ...

CVSS3: 6.7
github
около 3 лет назад

A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

6.7 Medium

CVSS3