PT-2022-3219 · Ntfs-3G+7 · Ntfs-3G+7
Roman Fiedler
·
Published
2022-05-16
·
Updated
2024-06-15
·
CVE-2022-30783
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NTFS-3G versions through 2021.8.22
Description
The issue is related to an invalid return code in the
fuse kern mount function of the libfuse-lite library for the NTFS-3G file system, which enables the interception of libfuse-lite protocol traffic between NTFS-3G and the kernel. Exploitation of this issue may allow an attacker to execute arbitrary code with elevated privileges using a specially crafted request.Recommendations
For NTFS-3G versions through 2021.8.22, consider disabling the
fuse kern mount function as a temporary workaround until a patch is available. Restrict access to the libfuse-lite protocol to minimize the risk of exploitation. Avoid using the vulnerable function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Unchecked Return Value
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Ntfs-3G
Red Os
Suse
Ubuntu
Libfuse-Lite