Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

SUSE: 2021:2971-1 Important Security Fix for Ntfs-3g NTFSProgs

suse
Calendar Grey September 7, 2021
Scroller Suse
Crucial SUSE patch for ntfs-3g_ntfsprogs tackles major security flaws and weaknesses present in the application.
An update that fixes 21 vulnerabilities is now available

Summary

This update for ntfs-3g_ntfsprogs fixes the following issues: Update to version 2021.8.22 (bsc#1189720): * Fixed compile error when building with libfuse < 2.8.0 * Fixed obsolete macros in configure.ac * Signalled support of UTIME_OMIT to external libfuse2 * Fixed an improper macro usage in ntfscp.c * Updated the repository change in the README * Fixed vulnerability threats caused by maliciously tampered NTFS partitions * Security fixes: CVE-2021-33285, CVE-2021-33286, CVE-2021-33287, CVE-2021-33289, CVE-2021-35266, CVE-2021-35267, CVE-2021-35268, CVE-2021-35269, CVE-2021-39251, CVE-2021-39252, CVE-2021-39253, CVE_2021-39254, CVE-2021-39255, CVE-2021-39256, CVE-2021-39257, CVE-2021-39258, CVE-2021-39259, CVE-2021-39260, CVE-2021-39261, CVE-2021-39262, CVE-2021-39263.

References

#1189720

Cross- CVE-2019-9755 CVE-2021-33285 CVE-2021-33286

CVE-2021-33287 CVE-2021-33289 CVE-2021-35266

CVE-2021-35267 CVE-2021-35268 CVE-2021-35269

CVE-2021-39251 CVE-2021-39252 CVE-2021-39253

CVE-2021-39255 CVE-2021-39256 CVE-2021-39257

CVE-2021-39258 CVE-2021-39259 CVE-2021-39260

CVE-2021-39261 CVE-2021-39262 CVE-2021-39263

CVSS scores:

CVE-2019-9755 (NVD) : 7 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-9755 (SUSE): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products:

SUSE Linux Enterprise Workstation Extension 15-SP3

SUSE Linux Enterprise Workstation Extension 15-SP2

https://www.suse.com/security/cve/CVE-2019-9755.html

https://www.suse.com/security/cve/CVE-2021-33285.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:2971-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.