[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3268-1 ntfs-3g -- ntfs-3g

ID: oval:org.secpod.oval:def:602112Date: (C)2015-06-04   (M)2022-09-22
Class: PATCHFamily: unix




Tavis Ormandy discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing mount or umount with elevated privileges. A local user can take advantage of this flaw to overwrite arbitrary files and gain elevated privileges by accessing debugging features via the environment that would not normally be safe for unprivileged users.

Platform:
Debian 8.x
Debian 7.x
Product:
ntfs-3g
Reference:
DSA-3268-1
CVE-2015-3202
CVE    1
CVE-2015-3202
CPE    3
cpe:/o:debian:debian_linux:7.x
cpe:/o:debian:debian_linux:8.x
cpe:/a:ntfs-3g:ntfs-3g

© SecPod Technologies