PT-2021-5785 · Ntfs-3G+7 · Ntfs-3G+7
Published
2021-08-20
·
Updated
2023-01-13
·
CVE-2021-33287
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NTFS-3G versions prior to 2021.8.22
Description
A heap buffer overflow can occur when specially crafted NTFS attributes are read in the function
ntfs attr pread i(), allowing for writing to arbitrary memory or denial of service of the application. This issue may enable an attacker to access confidential data, compromise data integrity, and cause a denial of service.Recommendations
For versions prior to 2021.8.22, update to version 2021.8.22 or later to resolve the issue. As a temporary workaround, consider restricting access to the
ntfs attr pread i() function until a patch is available.Fix
DoS
Memory Corruption
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Ntfs-3G
Red Hat
Rocky Linux
Suse