Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-40284

Опубликовано: 31 окт. 2022
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.

A buffer overflow flaw was found in NTFS-3G. This issue occurs via a crafted metadata in an NTFS image that can cause code execution. A local attacker can exploit this issue if the NTFS-3G binary is setuid root. A physically proximate attacker can exploit this issue if the NTFS-3G software is configured to execute upon attachment of an external storage device. Also this vulnerability may allow an attacker using a maliciously crafted NTFS-formatted image file or external storage to potentially execute arbitrary privileged code, if the attacker has either local access and the ntfs-3g binary is setuid root, or if the attacker has physical access to an external port to a computer which is configured to run the ntfs-3g binary or one of the ntfsprogs tools when the external storage is plugged into the computer. This vulnerability results from incorrect validation of some of the NTFS metadata that could potentially cause buffer overflow, which could be exploited by an attacker.

Отчет

This flaw has a lower impact on Red Hat Enterprise Linux because the ntfs-3g tool is run in a supermin appliance, which is similar to a virtual machine instantiated on the fly, and it does not have the SUID bit set. Thus an attacker is very limited on what he can do to the vulnerable system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libguestfs-winsupportOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libguestfs-winsupportAffected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt-devel:av/libguestfs-winsupportAffected
Advanced Virtualization for RHEL 8.4.0.EUSvirtFixedRHSA-2023:540528.09.2023
Advanced Virtualization for RHEL 8.4.0.EUSvirt-develFixedRHSA-2023:540528.09.2023
Red Hat Enterprise Linux 8virt-develFixedRHSA-2023:526419.09.2023
Red Hat Enterprise Linux 8virtFixedRHSA-2023:526419.09.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsvirtFixedRHSA-2023:523919.09.2023
Red Hat Enterprise Linux 8.2 Advanced Update SupportvirtFixedRHSA-2023:558710.10.2023
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicevirtFixedRHSA-2023:558710.10.2023

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119->CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2236130NTFS-3G: buffer overflow issue in NTFS-3G can cause code execution via crafted metadata in an NTFS image

EPSS

Процентиль: 7%
0.0003
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 2 лет назад

A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.

CVSS3: 7.8
nvd
больше 2 лет назад

A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.

CVSS3: 7.8
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7.8
debian
больше 2 лет назад

A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted ...

suse-cvrf
больше 2 лет назад

Security update for ntfs-3g_ntfsprogs

EPSS

Процентиль: 7%
0.0003
Низкий

3.3 Low

CVSS3

Уязвимость CVE-2022-40284