CVE-2021-46790Out-of-bounds Write in Ntfs-3g

Severity
7.8HIGHNVD
EPSS
0.0%
top 86.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateJun 7

Description

ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debiantuxera/ntfs-3g< 1:2017.3.23AR.3-4+deb11u2+3
Ubuntutuxera/ntfs-3g< 1:2017.3.23-2ubuntu0.18.04.4+2
NVDtuxera/ntfs-3g2021.8.22

Also affects: Debian Linux 10.0, 11.0, Fedora 35, 36

🔴Vulnerability Details

4
OSV
ntfs-3g vulnerabilities2022-06-07
GHSA
GHSA-274j-jr8v-77f7: ntfsck in NTFS-3G through 20212022-05-03
OSV
CVE-2021-46790: ntfsck in NTFS-3G through 20212022-05-02
CVEList
CVE-2021-46790: ntfsck in NTFS-3G through 20212022-05-02

📋Vendor Advisories

5
Ubuntu
NTFS-3G vulnerabilities2022-06-07
Ubuntu
NTFS-3G vulnerability2022-05-30
Microsoft
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however it is shipped by some Linux distributio2022-05-10
Red Hat
ntfs-3g: heap-based buffer overflow in ntfsck2021-11-25
Debian
CVE-2021-46790: ntfs-3g - ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving b...2021
CVE-2021-46790 — Out-of-bounds Write in Tuxera Ntfs-3g | cvebase