F2Fs-Tools Project F2Fs-Tools vulnerabilities
6 known vulnerabilities affecting f2fs-tools_project/f2fs-tools.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2020-6108P3HIGHCVSS 7.8fixed in 1.14.0vF2fs-Tools F2fs.Fsck 1.132020-10-15
CVE-2020-6108 [HIGH] CWE-131 CVE-2020-6108: An exploitable code execution vulnerability exists in the fsck_chk_orphan_node functionality of F2fs
An exploitable code execution vulnerability exists in the fsck_chk_orphan_node functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause a heap buffer overflow resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv
CVE-2020-6105P3HIGHCVSS 7.8fixed in 1.14.0vF2fs-Tools F2fs.Fsck 1.132020-10-15
CVE-2020-6105 [HIGH] CWE-73 CVE-2020-6105: An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Too
An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause Information overwrite resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv
CVE-2020-6070P3HIGHCVSS 7.8v1.12.0vF2fs-tools-1.12.02020-08-10
CVE-2020-6070 [HIGH] CWE-131 CVE-2020-6070: An exploitable code execution vulnerability exists in the file system checking functionality of fsck
An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv
CVE-2020-6106P4MEDIUMCVSS 5.5fixed in 1.14.0vF2fs-Tools F2fs.Fsck 1.12, F2fs-Tools F2fs.Fsck 1.132020-10-15
CVE-2020-6106 [MEDIUM] CWE-131 CVE-2020-6106: An exploitable information disclosure vulnerability exists in the init_node_manager functionality of
An exploitable information disclosure vulnerability exists in the init_node_manager functionality of F2fs-Tools F2fs.Fsck 1.12 and 1.13. A specially crafted filesystem can be used to disclose information. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv
CVE-2020-6104P4MEDIUMCVSS 5.5fixed in 1.14.0vF2fs-Tools F2fs.Fsck 1.132020-10-15
CVE-2020-6104 [MEDIUM] CWE-125 CVE-2020-6104: An exploitable information disclosure vulnerability exists in the get_dnode_of_data functionality of
An exploitable information disclosure vulnerability exists in the get_dnode_of_data functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause information disclosure resulting in a information disclosure. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv
CVE-2020-6107P4MEDIUMCVSS 5.5fixed in 1.14.0vF2fs-Tools F2fs.Fsck 1.132020-10-15
CVE-2020-6107 [MEDIUM] CWE-253 CVE-2020-6107: An exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Too
An exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause an uninitialized read resulting in an information disclosure. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv