Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Ubuntu 18.04 LTS: USN-3914-1 Critical: NTFS-3G Heap Overflow

Ubuntu Large Esm H500
NTFS-3G could be made to crash or potentially run programs as anadministrator if executed with specially crafted arguments.
=========================================================================Ubuntu Security Notice USN-3914-1
March 21, 2019

ntfs-3g vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.10
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

NTFS-3G could be made to crash or potentially run programs as an
administrator if executed with specially crafted arguments.

Software Description:
- ntfs-3g: read/write NTFS driver for FUSE

Details:

A heap buffer overflow was discovered in NTFS-3G when executing it with a
relative mount point path that is too long. A local attacker could
potentially exploit this to execute arbitrary code as the administrator.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
  ntfs-3g                         1:2017.3.23-2ubuntu0.18.10.1

Ubuntu 18.04 LTS:
  ntfs-3g                         1:2017.3.23-2ubuntu0.18.04.1

Ubuntu 16.04 LTS:
  ntfs-3g                         1:2015.3.14AR.1-1ubuntu0.2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-3914-1
  CVE-2019-9755

Package Information:
  https://launchpad.net/ubuntu/+source/ntfs-3g/1:2017.3.23-2ubuntu0.18.10.1
  https://launchpad.net/ubuntu/+source/ntfs-3g/1:2017.3.23-2ubuntu0.18.04.1
  https://launchpad.net/ubuntu/+source/ntfs-3g/1:2015.3.14AR.1-1ubuntu0.2

Ubuntu 18.04 LTS: USN-3914-1 Critical: NTFS-3G Heap Overflow

ubuntu
Calendar Grey March 21, 2019
Dist Ubuntu Esm H88
A flaw in NTFS-3G presents a risk for local exploitation, which may lead to unauthorized code execution; ensure you install the latest security packages on Ubuntu.
NTFS-3G could be made to crash or potentially run programs as anadministrator if executed with specially crafted arguments.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10:   ntfs-3g                         1:2017.3.23-2ubuntu0.18.10.1 Ubuntu 18.04 LTS:   ntfs-3g                         1:2017.3.23-2ubuntu0.18.04.1 Ubuntu 16.04 LTS:   ntfs-3g                         1:2015.3.14AR.1-1ubuntu0.2 In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-3914-1

  CVE-2019-9755

Severity
critical
Lowest
Low
Medium
High
Critical

March 21, 2019

Package Information

  https://launchpad.net/ubuntu/+source/ntfs-3g/1:2017.3.23-2ubuntu0.18.10.1   https://launchpad.net/ubuntu/+source/ntfs-3g/1:2017.3.23-2ubuntu0.18.04.1   https://launchpad.net/ubuntu/+source/ntfs-3g/1:2015.3.14AR.1-1ubuntu0.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here