VDB

DEBIAN-CVE-2019-9755

DEBIAN-CVE-2019-9755 PUBLISHED CVSS 7 HIGH

An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.

Risk Scores

CVSS v3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:14ntfs-3g0, 0, 0
Debian:11ntfs-3g0, 0, 0
Debian:12ntfs-3g0, 0, 0
Debian:13ntfs-3g0, 0, 0

Timeline

  • Jun 5, 2019 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›