Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 33 2021-38d1b07839 NTFS-3G Moderate Buffer Overflow Fix

fedora
Calendar Grey September 7, 2021
Dist Fedora Esm H88
Upgrade NTFS-3G on Fedora 33 to address various security vulnerabilities and improve support for system-compressed files.
Update NTFS-3G to 2021.8.22 to fix multiple CVEs

Summary

System compression, also known as "Compact OS", is a Windows feature that

allows rarely modified files to be compressed using the XPRESS or LZX

compression formats. It is not built directly into NTFS but rather is

implemented using reparse points. This feature appeared in Windows 10 and it

appears that many Windows 10 systems have been using it by default.

This RPM contains a plugin which enables the NTFS-3G FUSE driver to

transparently read from system-compressed files. Currently, only reading is

supported. Compressing an existing file may be done by using the "compact"

utility on Windows.

Update NTFS-3G to 2021.8.22 to fix multiple CVEs

* Tue Aug 31 2021 Richard W.M. Jones - 1.0-7

- Rebuild for updated ntfs-3g CVE (RHBZ#1999788)

* Thu Jul 22 2021 Fedora Release Engineering - 1.0-6

- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild

* Tue Jan 26 2021 Fedora Release Engineering - 1.0-5

- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild

[ 1 ] Bug #1999788 - ntfs-3g: Multiple buffer overflows in all versions [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1999788

[ 2 ] Bug #1999869 - ntfs-3g-2021.8.22 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1999869

su -c 'dnf upgrade --advisory FEDORA-2021-38d1b07839' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 33
Version: 1.0
Release: 7.fc33
Summary: NTFS-3G plugin for reading "system compressed" files

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here