CVE-2021-33285

Name
CVE-2021-33285
Description
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted ntfs partition. The root cause is a missing consistency check after reading an MFT record : the "bytes_in_use" field should be less than the "bytes_allocated" field. When it is not, the parsing of the records proceeds into the wild.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-q759-8j5v-q5jp
MISC https://bugzilla.redhat.com/show_bug.cgi?id=2001608
MISC https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=988386
MISC https://www.openwall.com/lists/oss-security/2021/08/30/1
MLIST http://www.openwall.com/lists/oss-security/2021/08/30/1
DEBIAN https://www.debian.org/security/2021/dsa-4971
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/766ISTT3KCARKFUIQT7N6WV6T63XOKG3/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HSEKTKHO5HFZHWZNJNBJZA56472KRUZI/
Mailing List https://lists.debian.org/debian-lts-announce/2021/11/msg00013.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:tuxera:ntfs-3g:*:*:*:*:*:*:*:* ntfs-3g >= None < 2021.8.22

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ntfs-3g 3.14-main 2017.3.23-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ntfs-3g 3.13-main 2017.3.23-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ntfs-3g 3.12-main 2017.3.23-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ntfs-3g 3.11-main 2017.3.23-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable