UBUNTU-CVE-2022-30785
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-30785
UBUNTU-CVE-2022-30785
Summary:
Details: A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
References: https://ubuntu.com/security/CVE-2022-30785, https://www.openwall.com/lists/oss-security/2022/05/26/2, https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-6mv4-4v73-xw58, https://github.com/tuxera/ntfs-3g/releases, https://ubuntu.com/security/notices/USN-5463-1, https://ubuntu.com/security/notices/USN-5463-2, https://www.cve.org/CVERecord?id=CVE-2022-30785
Affected packages
Package
Name: ntfs-3g
Purl: pkg:deb/ubuntu/ntfs-3g@1:2013.1.13AR.1-2ubuntu2+esm3?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
