MGASA-2015-0422

    Dashboard / Vulnerabilities / MGASA-2015-0422

    MGASA-2015-0422

    Published: 2 Nov 2015Last Modified: 16 Apr 2026

    Summary: Updated exfat-utils package fixes security vulnerabilities

    Details: Fix heap overflow and endless loop in exfatfsck exfat-utils is a collection of tools to work with the exFAT filesystem. Fuzzing the exfatfsck with american fuzzy lop led to the discovery of a write heap overflow and an endless loop. Especially at risk are systems that are configured to run filesystem checks automatically on external devices like USB flash drives. A malformed input can cause a write heap overflow in the function verify_vbr_checksum. It might be possible to use this for code execution. Another malformed input can cause an endless loop, leading to a possible denial of service.

    Affected packages

    Package

    Name: exfat-utils

    Purl: pkg:rpm/mageia/exfat-utils?arch=source&distro=mageia-5

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.1.0-3.1.mga5

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High