CVE-2021-46790 — Out-of-bounds Write in Ntfs-3g
Severity
7.8HIGHNVD
EPSS
0.0%
top 86.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateJun 7
Description
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages3 packages
Also affects: Debian Linux 10.0, 11.0, Fedora 35, 36
🔴Vulnerability Details
4📋Vendor Advisories
5Microsoft▶
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however it is shipped by some Linux distributio↗2022-05-10
Debian▶
CVE-2021-46790: ntfs-3g - ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving b...↗2021