cbcvebase.
CVE-2019-9755
published 2019-06-05

CVE-2019-9755: An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted…

high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianntfs-3g< ntfs-3g 1:2017.3.23AR.3-3 (bookworm)ntfs-3g 1:2017.3.23AR.3-3 (bookworm)
msrccbl2_ntfs-3g_2017.3.23-15_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
tuxerantfs-3g
tuxerantfs-3g>= 0 < 1:2017.3.23AR.3-31:2017.3.23AR.3-3
tuxerantfs-3g>= 0 < 1:2017.3.23AR.3-31:2017.3.23AR.3-3
tuxerantfs-3g>= 0 < 1:2017.3.23AR.3-31:2017.3.23AR.3-3
tuxerantfs-3g>= 0 < 1:2017.3.23AR.3-31:2017.3.23AR.3-3

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH