cbcvebase.

Debian Ntfs-3G vulnerabilities

35 known vulnerabilities affecting debian/ntfs-3g.

Total CVEs
35
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH28MEDIUM6LOW1

Vulnerabilities

Page 2 of 2
CVE-2021-39258P3HIGHCVSS 7.8fixed in ntfs-3g 1:2021.8.22-2 (bookworm)2021
CVE-2021-39258 [HIGH] CVE-2021-39258: ntfs-3g - A crafted NTFS image can cause out-of-bounds reads in ntfs_attr_find and ntfs_ex... A crafted NTFS image can cause out-of-bounds reads in ntfs_attr_find and ntfs_external_attr_find in NTFS-3G < 2021.8.22. Scope: local bookworm: resolved (fixed in 1:2021.8.22-2) bullseye: resolved (fixed in 1:2017.3.23AR.3-4+deb11u1) forky: resolved (fixed in 1:2021.8.22-2) sid: resolved (fixed in 1:2021.8.22-2) trixie: resolved (fixed in 1:2021.8.22-2)
debian
CVE-2021-39259P3HIGHCVSS 7.8fixed in ntfs-3g 1:2021.8.22-2 (bookworm)2021
CVE-2021-39259 [HIGH] CVE-2021-39259: ntfs-3g - A crafted NTFS image can trigger an out-of-bounds access, caused by an unsanitiz... A crafted NTFS image can trigger an out-of-bounds access, caused by an unsanitized attribute length in ntfs_inode_lookup_by_name, in NTFS-3G < 2021.8.22. Scope: local bookworm: resolved (fixed in 1:2021.8.22-2) bullseye: resolved (fixed in 1:2017.3.23AR.3-4+deb11u1) forky: resolved (fixed in 1:2021.8.22-2) sid: resolved (fixed in 1:2021.8.22-2) trixie: resolved (fix
debian
CVE-2022-30784P3HIGHCVSS 7.8fixed in ntfs-3g 1:2022.5.17-1 (bookworm)2022
CVE-2022-30784 [HIGH] CVE-2022-30784: ntfs-3g - A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NT... A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22. Scope: local bookworm: resolved (fixed in 1:2022.5.17-1) bullseye: resolved (fixed in 1:2017.3.23AR.3-4+deb11u2) forky: resolved (fixed in 1:2022.5.17-1) sid: resolved (fixed in 1:2022.5.17-1) trixie: resolved (fixed in 1:2022.5.17-1)
debian
CVE-2021-39252P3HIGHCVSS 7.8fixed in ntfs-3g 1:2021.8.22-2 (bookworm)2021
CVE-2021-39252 [HIGH] CVE-2021-39252: ntfs-3g - A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3... A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22. Scope: local bookworm: resolved (fixed in 1:2021.8.22-2) bullseye: resolved (fixed in 1:2017.3.23AR.3-4+deb11u1) forky: resolved (fixed in 1:2021.8.22-2) sid: resolved (fixed in 1:2021.8.22-2) trixie: resolved (fixed in 1:2021.8.22-2)
debian
CVE-2021-39253P3HIGHCVSS 7.8fixed in ntfs-3g 1:2021.8.22-2 (bookworm)2021
CVE-2021-39253 [HIGH] CVE-2021-39253: ntfs-3g - A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in... A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22. Scope: local bookworm: resolved (fixed in 1:2021.8.22-2) bullseye: resolved (fixed in 1:2017.3.23AR.3-4+deb11u1) forky: resolved (fixed in 1:2021.8.22-2) sid: resolved (fixed in 1:2021.8.22-2) trixie: resolved (fixed in 1:2021.8.22-2)
debian
CVE-2021-33287P3HIGHCVSS 7.8fixed in ntfs-3g 1:2021.8.22-2 (bookworm)2021
CVE-2021-33287 [HIGH] CVE-2021-33287: ntfs-3g - In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read... In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application. Scope: local bookworm: resolved (fixed in 1:2021.8.22-2) bullseye: resolved (fixed in 1:2017.3.23AR.3-4+deb11u1) forky: resolved (fixed
debian
CVE-2021-39255P3HIGHCVSS 7.8fixed in ntfs-3g 1:2021.8.22-2 (bookworm)2021
CVE-2021-39255 [HIGH] CVE-2021-39255: ntfs-3g - A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid att... A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid attribute in ntfs_attr_find_in_attrdef, in NTFS-3G < 2021.8.22. Scope: local bookworm: resolved (fixed in 1:2021.8.22-2) bullseye: resolved (fixed in 1:2017.3.23AR.3-4+deb11u1) forky: resolved (fixed in 1:2021.8.22-2) sid: resolved (fixed in 1:2021.8.22-2) trixie: resolved (fixed in 1:2021.
debian
CVE-2021-39251P3HIGHCVSS 7.8fixed in ntfs-3g 1:2021.8.22-2 (bookworm)2021
CVE-2021-39251 [HIGH] CVE-2021-39251: ntfs-3g - A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_o... A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22. Scope: local bookworm: resolved (fixed in 1:2021.8.22-2) bullseye: resolved (fixed in 1:2017.3.23AR.3-4+deb11u1) forky: resolved (fixed in 1:2021.8.22-2) sid: resolved (fixed in 1:2021.8.22-2) trixie: resolved (fixed in 1:2021.8.22-2)
debian
CVE-2019-9755P4HIGHCVSS 7.0fixed in ntfs-3g 1:2017.3.23AR.3-3 (bookworm)2019
CVE-2019-9755 [HIGH] CVE-2019-9755: ntfs-3g - An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could p... An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead t
debian
CVE-2022-30785P4MEDIUMCVSS 6.7fixed in ntfs-3g 1:2022.5.17-1 (bookworm)2022
CVE-2022-30785 [MEDIUM] CVE-2022-30785: ntfs-3g - A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, e... A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite. Scope: local bookworm: resolved (fixed in 1:2022.5.17-1) bullseye: resolved (fixed in 1:2017.3.23AR.3-4+deb11u2) forky: resolved (fixed in 1:2022.5.17-1) sid: resolved (fixed in 1:20
debian
CVE-2022-30787P4MEDIUMCVSS 6.7fixed in ntfs-3g 1:2022.5.17-1 (bookworm)2022
CVE-2022-30787 [MEDIUM] CVE-2022-30787: ntfs-3g - An integer underflow in fuse_lib_readdir enables arbitrary memory read operation... An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite. Scope: local bookworm: resolved (fixed in 1:2022.5.17-1) bullseye: resolved (fixed in 1:2017.3.23AR.3-4+deb11u2) forky: resolved (fixed in 1:2022.5.17-1) sid: resolved (fixed in 1:2022.5.17-1) trixie: resolved (fixed in 1:2022.5.1
debian
CVE-2022-30783P4MEDIUMCVSS 6.7fixed in ntfs-3g 1:2022.5.17-1 (bookworm)2022
CVE-2022-30783 [MEDIUM] CVE-2022-30783: ntfs-3g - An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite p... An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite. Scope: local bookworm: resolved (fixed in 1:2022.5.17-1) bullseye: resolved (fixed in 1:2017.3.23AR.3-4+deb11u2) forky: resolved (fixed in 1:2022.5.17-1) sid: resolved (fixed in 1:2022.
debian
CVE-2021-39257P4MEDIUMCVSS 5.5fixed in ntfs-3g 1:2021.8.22-2 (bookworm)2021
CVE-2021-39257 [MEDIUM] CVE-2021-39257: ntfs-3g - A crafted NTFS image with an unallocated bitmap can lead to a endless recursive ... A crafted NTFS image with an unallocated bitmap can lead to a endless recursive function call chain (starting from ntfs_attr_pwrite), causing stack consumption in NTFS-3G < 2021.8.22. Scope: local bookworm: resolved (fixed in 1:2021.8.22-2) bullseye: resolved (fixed in 1:2017.3.23AR.3-4+deb11u1) forky: resolved (fixed in 1:2021.8.22-2) sid: resolved (fixed in 1:20
debian
CVE-2023-52890P4MEDIUMCVSS 4.5fixed in ntfs-3g 1:2022.10.3-1+deb12u1 (bookworm)2023
CVE-2023-52890 [MEDIUM] CVE-2023-52890: ntfs-3g - NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/... NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging. Scope: local bookworm: resolved (fixed in 1:2022.10.3-1+deb12u1) bullseye: resolved (fixed in 1:2017.3.23AR.3-4+deb11u4) forky: resolved (fixed in 1:2022.10.3-3) sid: resolved (fixed in 1:2022.10.3-3) trixie: r
debian
CVE-2007-5159P4MEDIUMCVSS 4.6fixed in ntfs-3g 1:1.913-2 (bookworm)2007
CVE-2007-5159 [MEDIUM] CVE-2007-5159: ntfs-3g - The ntfs-3g package before 1.913-2.fc7 in Fedora 7, and an ntfs-3g package in Ub... The ntfs-3g package before 1.913-2.fc7 in Fedora 7, and an ntfs-3g package in Ubuntu 7.10/Gutsy, assign incorrect permissions (setuid root) to mount.ntfs-3g, which allows local users with fuse group membership to read from and write to arbitrary block devices, possibly involving a file descriptor leak. Scope: local bookworm: resolved (fixed in 1:1.913-2) bullseye: r
debian
Debian Ntfs-3G vulnerabilities | cvebase