Alerts This Week
Warning Icon 1 640
Alerts This Week
Warning Icon 1 640

Ubuntu 18.04 LTS: USN-3914-1 Critical: NTFS-3G Heap Overflow

ubuntu
Calendar Grey March 21, 2019
Dist Ubuntu Esm H88
A flaw in NTFS-3G presents a risk for local exploitation, which may lead to unauthorized code execution; ensure you install the latest security packages on Ubuntu.
NTFS-3G could be made to crash or potentially run programs as anadministrator if executed with specially crafted arguments.

Summary

NTFS-3G could be made to crash or potentially run programs as an

administrator if executed with specially crafted arguments.

Software Description:

- ntfs-3g: read/write NTFS driver for FUSE

Details:

A heap buffer overflow was discovered in NTFS-3G when executing it with a

relative mount point path that is too long. A local attacker could

potentially exploit this to execute arbitrary code as the administrator.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
  ntfs-3g                         1:2017.3.23-2ubuntu0.18.10.1

Ubuntu 18.04 LTS:
  ntfs-3g                         1:2017.3.23-2ubuntu0.18.04.1

Ubuntu 16.04 LTS:
  ntfs-3g                         1:2015.3.14AR.1-1ubuntu0.2

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-3914-1

  CVE-2019-9755

Severity
critical
Lowest
Low
Medium
High
Critical

March 21, 2019

Package Information

  https://launchpad.net/ubuntu/+source/ntfs-3g/1:2017.3.23-2ubuntu0.18.10.1
  https://launchpad.net/ubuntu/+source/ntfs-3g/1:2017.3.23-2ubuntu0.18.04.1
  https://launchpad.net/ubuntu/+source/ntfs-3g/1:2015.3.14AR.1-1ubuntu0.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here