MidnightBSD

Advisories for tuxera

CVE-2017-0358 HIGH

Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-269,CWE-269,

Products Affected

Vendor Product Version
tuxera ntfs-3g *
debian debian_linux 8.0
CVE-2019-9755 MEDIUM

An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.0 HIGH CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H 1.0 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-191,CWE-787,

Products Affected

Vendor Product Version
redhat enterprise_linux 8.0
tuxera ntfs-3g 2017.3.23
redhat enterprise_linux_server_tus 8.4
redhat enterprise_linux_eus 8.4
redhat enterprise_linux_server_aus 8.4
redhat enterprise_linux_server 7.0
redhat enterprise_linux_eus 8.2
redhat enterprise_linux_server_aus 8.2
redhat enterprise_linux_eus 8.1
redhat enterprise_linux_server_tus 8.2