MGASA-2022-0001

Source
https://advisories.mageia.org/MGASA-2022-0001.html
Import Source
https://advisories.mageia.org/MGASA-2022-0001.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2022-0001
Related
Published
2022-01-03T07:36:40Z
Modified
2022-01-03T06:58:31Z
Summary
Updated ntfs-3g packages fix security vulnerability
Details

Security vulnerabilities were identified in the open source NTFS-3G and NTFSPROGS software. These vulnerabilities may allow an attacker using a maliciously crafted NTFS-formatted image file or external storage to potentially execute arbitrary privileged code, if the attacker has either local access and the ntfs-3g binary is setuid root, or if the attacker has physical access to an external port to a computer which is configured to run the ntfs-3g binary or one of the ntfsprogs tools when the external storage is plugged into the computer. These vulnerabilities result from incorrect validation of some of the NTFS metadata that could potentially cause buffer overflows, which could be exploited by an attacker. Common ways for attackers to gain physical access to a machine is through social engineering or an evil maid attack on an unattended computer.

References
Credits

Affected packages

Mageia:8 / ntfs-3g

Package

Name
ntfs-3g
Purl
pkg:rpm/mageia/ntfs-3g?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2021.8.22-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / libguestfs

Package

Name
libguestfs
Purl
pkg:rpm/mageia/libguestfs?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.44.0-2.2.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / wimlib

Package

Name
wimlib
Purl
pkg:rpm/mageia/wimlib?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.13.3-1.2.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / partclone

Package

Name
partclone
Purl
pkg:rpm/mageia/partclone?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.3.18-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / ntfs-3g-system-compression

Package

Name
ntfs-3g-system-compression
Purl
pkg:rpm/mageia/ntfs-3g-system-compression?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0-1.2.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / testdisk

Package

Name
testdisk
Purl
pkg:rpm/mageia/testdisk?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.1-2.2.mga8

Ecosystem specific

{
    "section": "core"
}