CVE-2022-40284

Name
CVE-2022-40284
Description
A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC http://www.openwall.com/lists/oss-security/2022/10/31/2
MISC https://github.com/tuxera/ntfs-3g/releases
MLIST https://lists.debian.org/debian-lts-announce/2022/11/msg00029.html
Third Party Advisory https://security.gentoo.org/glsa/202301-01
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IA2D4PYOR7ABI7BWBMMMYKY2OPHTV2NI/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2BOQ7YLFT43KLXEN3EB6CS4DP635RJWP/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UGDKGXA4R2ZVUQ3CT4D4YGTFMNZQA7HW/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:tuxera:ntfs-3g:*:*:*:*:*:*:*:* ntfs-3g >= None < 2022.10.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ntfs-3g 3.16-main 2022.5.17-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ntfs-3g 3.15-main 2021.8.22-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ntfs-3g 3.14-main 2017.3.23-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ntfs-3g 3.13-main 2017.3.23-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ntfs-3g 3.17-main 2022.10.3-r0 Natanael Copa <ncopa@alpinelinux.org> fixed