CVE-2016-4804
published 2016-06-03CVE-2016-4804: The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a…
PriorityP420medium6.2CVSS 3.0
AVLACLPRNUINSUCNINAH
EPSS
0.45%
36.7th percentile
The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | dosfstools | < dosfstools 4.0-1 (bookworm) | dosfstools 4.0-1 (bookworm) |
| dosfstools_project | dosfstools | <= 3.0.28 | — |
| dosfstools_project | dosfstools | >= 0 < 4.0-1 | 4.0-1 |
| dosfstools_project | dosfstools | >= 0 < 4.0-1 | 4.0-1 |
| dosfstools_project | dosfstools | >= 0 < 4.0-1 | 4.0-1 |
| dosfstools_project | dosfstools | >= 0 < 4.0-1 | 4.0-1 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.06.2MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q73q-vv6v-g3cp: The read_boot function in boot
ghsa_unreviewed·2022-05-13
CVE-2016-4804 [MEDIUM] CWE-119 GHSA-q73q-vv6v-g3cp: The read_boot function in boot
The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function.
OSV
CVE-2016-4804: The read_boot function in boot
osv·2016-06-03·CVSS 6.2
CVE-2016-4804 [MEDIUM] CVE-2016-4804: The read_boot function in boot
The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function.
Ubuntu
dosfstools vulnerabilities
vendor_ubuntu·2016-05-31
CVE-2015-8872 dosfstools vulnerabilities
Title: dosfstools vulnerabilities
Summary: dosfstools could be made to crash or run programs if it processed a
specially crafted filesystem.
Hanno Böck discovered that dosfstools incorrectly handled certain malformed
filesystems. A local attacker could use this issue to cause dosfstools to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dosfstools: Heap-buffer-overflows in read_fat() and get_fat() functions
vendor_redhat·2016-05-14·CVSS 6.2
CVE-2016-4804 [MEDIUM] CWE-122 dosfstools: Heap-buffer-overflows in read_fat() and get_fat() functions
dosfstools: Heap-buffer-overflows in read_fat() and get_fat() functions
The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function.
Package: dosfstools (Red Hat Enterprise Linux 5) - Will not fix
Package: dosfstools (Red Hat Enterprise Linux 6) - Will not fix
Package: dosfstools (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-4804: dosfstools - The read_boot function in boot.c in dosfstools before 4.0 allows attackers to ca...
vendor_debian·2016·CVSS 6.2
CVE-2016-4804 [MEDIUM] CVE-2016-4804: dosfstools - The read_boot function in boot.c in dosfstools before 4.0 allows attackers to ca...
The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function.
Scope: local
bookworm: resolved (fixed in 4.0-1)
bullseye: resolved (fixed in 4.0-1)
forky: resolved (fixed in 4.0-1)
sid: resolved (fixed in 4.0-1)
trixie: resolved (fixed in 4.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8872 CVE-2016-4804 dosfstools: various flaws [fedora-all]
bugzilla·2016-05-19·CVSS 6.2
CVE-2015-8872 [MEDIUM] CVE-2015-8872 CVE-2016-4804 dosfstools: various flaws [fedora-all]
CVE-2015-8872 CVE-2016-4804 dosfstools: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2016-4804 dosfstools: Heap-buffer-overflows in read_fat() and get_fat() functions
bugzilla·2016-05-17·CVSS 6.2
CVE-2016-4804 [MEDIUM] CVE-2016-4804 dosfstools: Heap-buffer-overflows in read_fat() and get_fat() functions
CVE-2016-4804 dosfstools: Heap-buffer-overflows in read_fat() and get_fat() functions
Multiple vulnerabilities were found in dosfstools. The variable used for storing the FAT size (in bytes) was an unsignedint. Since the size in sectors read from the BPB was not sufficiently checked, this could end up being zero after multiplying it with the sector size while some offsets still stayed excessive. Ultimately it would cause segfaults when accessing FAT entries for which no memory
was allocated.
External references:
https://github.com/dosfstools/dosfstools/issues/25
https://github.com/dosfstools/dosfstools/issues/26
https://blog.fuzzing-project.org/44-dosfstools-fsck.vfat-Several-invalid-memory-accesses.html
Upstream fix:
https://github.com/dosfstools/dosfstools/commit/e8eff147e9da1185f9
http://lists.opensuse.org/opensuse-updates/2016-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2016-09/msg00014.htmlhttp://www.securityfocus.com/bid/90311http://www.ubuntu.com/usn/USN-2986-1https://blog.fuzzing-project.org/44-dosfstools-fsck.vfat-Several-invalid-memory-accesses.htmlhttps://github.com/dosfstools/dosfstools/commit/e8eff147e9da1185f9afd5b25948153a3b97cf52https://github.com/dosfstools/dosfstools/issues/25https://github.com/dosfstools/dosfstools/issues/26https://lists.debian.org/debian-lts-announce/2020/05/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2016-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2016-09/msg00014.htmlhttp://www.securityfocus.com/bid/90311http://www.ubuntu.com/usn/USN-2986-1https://blog.fuzzing-project.org/44-dosfstools-fsck.vfat-Several-invalid-memory-accesses.htmlhttps://github.com/dosfstools/dosfstools/commit/e8eff147e9da1185f9afd5b25948153a3b97cf52https://github.com/dosfstools/dosfstools/issues/25https://github.com/dosfstools/dosfstools/issues/26https://lists.debian.org/debian-lts-announce/2020/05/msg00028.html
2016-06-03
Published