6.8
CVSSv2

CVE-2020-6108

Published: 15/10/2020 Updated: 12/05/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An exploitable code execution vulnerability exists in the fsck_chk_orphan_node functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause a heap buffer overflow resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

f2fs-tools project f2fs-tools

Vendor Advisories

Debian Bug report logs - #973380 CVE-2020-6104 CVE-2020-6105 CVE-2020-6106 CVE-2020-6107 CVE-2020-6108 Package: f2fs-tools; Maintainer for f2fs-tools is Filesystems Group <filesystems-devel@listsaliothdebianorg>; Source for f2fs-tools is src:f2fs-tools (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debiano ...