USN-5452-1: NTFS-3G vulnerability
30 May 2022
NTFS-3G could be made to crash or run programs if it opened a specially crafted file.
Releases
Packages
- ntfs-3g - read/write NTFS driver for FUSE
Details
It was discovered that NTFS-3G was incorrectly validating NTFS
metadata in its ntfsck tool by not performing boundary checks. A
local attacker could possibly use this issue to cause a denial of
service or to execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
ntfs-3g
-
1:2015.3.14AR.1-1ubuntu0.3+esm2
Available with Ubuntu Pro
-
ntfs-3g-dev
-
1:2015.3.14AR.1-1ubuntu0.3+esm2
Available with Ubuntu Pro
Ubuntu 14.04
-
ntfs-3g
-
1:2013.1.13AR.1-2ubuntu2+esm2
Available with Ubuntu Pro
-
ntfs-3g-dev
-
1:2013.1.13AR.1-2ubuntu2+esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-5463-1: libntfs-3g883, libntfs-3g88, libntfs-3g89, ntfs-3g-dev, ntfs-3g