Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-30786

Опубликовано: 26 мая 2022
Источник: redhat
CVSS3: 7.8

Описание

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.

A vulnerability was found in NTFS-3G. Incorrect validation of NTFS metadata can result in a heap-based buffer overflow when processing a crafted NTFS image file or partition.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libguestfs-winsupportOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/libguestfs-winsupportWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libguestfs-winsupportWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt-devel:8.2/libguestfs-winsupportWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt-devel:av/libguestfs-winsupportWill not fix
Red Hat Enterprise Linux 8virt-develFixedRHSA-2023:275716.05.2023
Red Hat Enterprise Linux 8virtFixedRHSA-2023:275716.05.2023
Red Hat Enterprise Linux 9libguestfs-winsupportFixedRHSA-2023:217909.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2093326ntfs-3g: crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 3 лет назад

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.

CVSS3: 7.8
nvd
около 3 лет назад

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.

CVSS3: 7.8
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 7.8
debian
около 3 лет назад

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_na ...

CVSS3: 6.8
github
около 3 лет назад

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.

7.8 High

CVSS3

Уязвимость CVE-2022-30786