383
VMScore

CVE-2020-6104

Published: 15/10/2020 Updated: 12/05/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An exploitable information disclosure vulnerability exists in the get_dnode_of_data functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause information disclosure resulting in a information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

f2fs-tools project f2fs-tools

Vendor Advisories

Debian Bug report logs - #973380 CVE-2020-6104 CVE-2020-6105 CVE-2020-6106 CVE-2020-6107 CVE-2020-6108 Package: f2fs-tools; Maintainer for f2fs-tools is Filesystems Group <filesystems-devel@listsaliothdebianorg>; Source for f2fs-tools is src:f2fs-tools (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debiano ...