Tuxera NTFS-3G 2021.8.22

CPE Details

Tuxera NTFS-3G 2021.8.22
2021.8.22
2021-11-29
17h19 +00:00
2022-02-08
16h28 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:tuxera:ntfs-3g:2021.8.22:*:*:*:*:*:*:*

Informations

Vendor

tuxera

Product

ntfs-3g

Version

2021.8.22

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-40284 2022-11-05 23h00 +00:00 A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.
7.8
High
CVE-2022-30783 2022-05-25 22h00 +00:00 An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite.
6.7
Medium
CVE-2022-30784 2022-05-25 22h00 +00:00 A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.
7.8
High
CVE-2022-30785 2022-05-25 22h00 +00:00 A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
6.7
Medium
CVE-2022-30786 2022-05-25 22h00 +00:00 A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.
7.8
High
CVE-2022-30787 2022-05-25 22h00 +00:00 An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
6.7
Medium
CVE-2022-30788 2022-05-25 22h00 +00:00 A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.
7.8
High
CVE-2022-30789 2022-05-25 22h00 +00:00 A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.
7.8
High
CVE-2021-46790 2022-05-02 03h10 +00:00 ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.
7.8
High