6.2
CVSSv3

CVE-2016-4804

Published: 03/06/2016 Updated: 30/05/2020
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.2 | Impact Score: 3.6 | Exploitability Score: 2.5
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The read_boot function in boot.c in dosfstools prior to 4.0 allows malicious users to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dosfstools project dosfstools

opensuse leap 42.1

opensuse opensuse 13.2

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

canonical ubuntu linux 16.04

canonical ubuntu linux 15.10

Vendor Advisories

dosfstools could be made to crash or run programs if it processed a specially crafted filesystem ...