ALPINE-CVE-2019-9755 PUBLISHED CVSS 7 HIGH

An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.

Risk Scores

CVSS v3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.9ntfs-3g2010.3.6-r0, 2017.3.23-r0, 0
Alpine:v3.16ntfs-3g2010.8.8-r0, 2017.3.23-r1, 2017.3.23-r0
Alpine:v3.15ntfs-3g2009.11.14-r0, 0, 2017.3.23-r1
Alpine:v3.17ntfs-3g2017.3.23-r0, 2017.3.23-r1, 0
Alpine:v3.22ntfs-3g2014.2.15-r0, 2017.3.23-r1, 2017.3.23-r0
Alpine:v3.19ntfs-3g2009.11.14-r0, 0, 2009.4.4-r0
Alpine:v3.23ntfs-3g2017.3.23-r1, 2009.11.14-r0, 2009.4.4-r0
Alpine:v3.10ntfs-3g2011.1.15-r0, 2017.3.23-r1, 2017.3.23-r0
Alpine:v3.11ntfs-3g2017.3.23-r1, 2009.4.4-r0, 2010.3.6-r0
Alpine:v3.20ntfs-3g0, 2009.11.14-r0, 2009.4.4-r0
Alpine:v3.12ntfs-3g2017.3.23-r1, 2017.3.23-r0, 2016.2.22-r1
Alpine:v3.21ntfs-3g0, 2009.11.14-r0, 2009.4.4-r0
Alpine:v3.14ntfs-3g2017.3.23-r1, 2017.3.23-r0, 2016.2.22-r1
Alpine:v3.18ntfs-3g2009.4.4-r0, 2017.3.23-r1, 2017.3.23-r0
Alpine:v3.13ntfs-3g0, 2017.3.23-r1, 2017.3.23-r0
Alpine:v3.8ntfs-3g0, 2009.4.4-r0, 2010.10.2-r0

Timeline

References

Open in Interactive Console →