PT-2020-6546 · Unknown+1 · F2Fs-Tools+1

Published

2020-08-27

·

Updated

2024-10-18

·

CVE-2020-6105

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions F2fs-Tools versions 1.13
Description The issue is related to incorrect external management of file names or paths, which can be exploited to delete arbitrary files by creating a specially crafted f2fs filesystem. A specially crafted f2fs filesystem can cause information overwrite, resulting in code execution. An attacker can provide a malicious file to trigger this vulnerability.
Recommendations For version 1.13, consider restricting the use of the F2fs.Fsck functionality until a patch is available. As a temporary workaround, avoid using F2fs-Tools to handle untrusted or malicious filesystems.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2693
ALT-PU-2024-13883
BDU:2021-06199
CVE-2020-6105

Affected Products

Alt Linux
F2Fs-Tools