7
CVSSv3

CVE-2019-9755

Published: 05/06/2019 Updated: 26/04/2022
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A heap buffer overflow exists in NTFS-3G when executing it with a relative mount point path that is too long. A local attacker could potentially exploit this to execute arbitrary code as the administrator.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tuxera ntfs-3g 2017.3.23

redhat enterprise linux server 7.0

redhat enterprise linux 8.0

redhat enterprise linux eus 8.1

redhat enterprise linux eus 8.2

redhat enterprise linux server tus 8.2

redhat enterprise linux server aus 8.2

redhat enterprise linux server tus 8.4

redhat enterprise linux eus 8.4

redhat enterprise linux server aus 8.4

Vendor Advisories

Debian Bug report logs - #925255 ntfs-3g: CVE-2019-9755: heap buffer overflow Package: src:ntfs-3g; Maintainer for src:ntfs-3g is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 21 Mar 2019 20:57:02 UTC Severity: grave Tags: fixed-upstream, security, upstrea ...
NTFS-3G could be made to crash or potentially run programs as an administrator if executed with specially crafted arguments ...
Synopsis Low: libguestfs-winsupport security update Type/Severity Security Advisory: Low Topic An update for libguestfs-winsupport is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) b ...
Synopsis Low: virt:rhel security, bug fix, and enhancement update Type/Severity Security Advisory: Low Topic An update for the virt:rhel module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring Sy ...
A heap-based buffer overflow was discovered in NTFS-3G, a read-write NTFS driver for FUSE A local user can take advantage of this flaw for local root privilege escalation For the stable distribution (stretch), this problem has been fixed in version 1:2016222AR1+dfsg-1+deb9u1 We recommend that you upgrade your ntfs-3g packages For the detaile ...
An integer underflow issue exists in ntfs-3g 2017323 A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code In installations where /bin/ntfs-3g is a setuid-root binar ...