USN-5463-2
Dashboard / Vulnerabilities / USN-5463-2
USN-5463-2
Summary: ntfs-3g vulnerabilities
Details: USN-5463-1 fixed vulnerabilities in NTFS-3G. This update provides the corresponding updates for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: Roman Fiedler discovered that NTFS-3G incorrectly handled certain return codes. A local attacker could possibly use this issue to intercept protocol traffic between FUSE and the kernel. (CVE-2022-30783) It was discovered that NTFS-3G incorrectly handled certain NTFS disk images. If a user or automated system were tricked into mounting a specially crafted disk image, a remote attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2022-30784, CVE-2022-30786, CVE-2022-30788, CVE-2022-30789) Roman Fiedler discovered that NTFS-3G incorrectly handled certain file handles. A local attacker could possibly use this issue to read and write arbitrary memory. (CVE-2022-30785, CVE-2022-30787)
References: https://ubuntu.com/security/notices/USN-5463-2, https://ubuntu.com/security/CVE-2022-30783, https://ubuntu.com/security/CVE-2022-30784, https://ubuntu.com/security/CVE-2022-30785, https://ubuntu.com/security/CVE-2022-30786, https://ubuntu.com/security/CVE-2022-30787, https://ubuntu.com/security/CVE-2022-30788, https://ubuntu.com/security/CVE-2022-30789
Affected packages
Package
Name: ntfs-3g
Purl: pkg:deb/ubuntu/ntfs-3g?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
