Show filters
33 Total Results
Displaying 31-33 of 33
Sort by:
Attacker Value
Unknown
CVE-2019-9755
Disclosure Date: June 05, 2019 (last updated November 27, 2024)
An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.
0
Attacker Value
Unknown
ntfs-3g: Modprobe influence vulnerability via environment variables
Disclosure Date: April 13, 2018 (last updated November 26, 2024)
Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.
0
Attacker Value
Unknown
CVE-2007-5159
Disclosure Date: October 01, 2007 (last updated October 04, 2023)
The ntfs-3g package before 1.913-2.fc7 in Fedora 7, and an ntfs-3g package in Ubuntu 7.10/Gutsy, assign incorrect permissions (setuid root) to mount.ntfs-3g, which allows local users with fuse group membership to read from and write to arbitrary block devices, possibly involving a file descriptor leak.
0