Description
A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22.
References
https://github.com/tuxera/ntfs-3g/releases
Release NotesThird Party Advisory
https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-q759-8j5v-q5jp
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/11/msg00013.html
Mailing ListThird Party Advisory
https://security.gentoo.org/glsa/202301-01
Third Party Advisory
https://www.debian.org/security/2021/dsa-4971
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8 · High
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Modified
Published
2021-09-07T15:15:07.917
3 years agoLast modified
2023-11-07T03:37:38.290
1 year ago