Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-9755

Опубликовано: 05 июн. 2019
Источник: ubuntu
Приоритет: high
EPSS Низкий
CVSS2: 4.4
CVSS3: 7

Описание

An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.

РелизСтатусПримечание
bionic

released

1:2017.3.23-2ubuntu0.18.04.1
cosmic

released

1:2017.3.23-2ubuntu0.18.10.1
devel

released

1:2017.3.23AR.3-2ubuntu1
esm-infra-legacy/trusty

ignored

esm-infra/bionic

not-affected

1:2017.3.23-2ubuntu0.18.04.1
esm-infra/xenial

not-affected

1:2015.3.14AR.1-1ubuntu0.2
precise/esm

ignored

trusty

ignored

trusty/esm

ignored

upstream

released

2017.3.23AR.4

Показывать по

EPSS

Процентиль: 29%
0.00103
Низкий

4.4 Medium

CVSS2

7 High

CVSS3

Связанные уязвимости

CVSS3: 3.3
redhat
больше 6 лет назад

An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.

CVSS3: 7
nvd
около 6 лет назад

An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.

CVSS3: 7
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7
debian
около 6 лет назад

An integer underflow issue exists in ntfs-3g 2017.3.23. A local attack ...

suse-cvrf
больше 6 лет назад

Security update for ntfs-3g_ntfsprogs

EPSS

Процентиль: 29%
0.00103
Низкий

4.4 Medium

CVSS2

7 High

CVSS3