It was discovered that there was both an invalid memory and heap overflow vulnerability in dosfstools, a collection of utilities for making and checking MS-DOS FAT filesystems. . Package : dosfstools Version : 3.0.27-1+deb8u1 CVE ID : CVE-2015-8872 CVE-2016-4804 It was discovered that there was both an invalid memory and heap overflow vulnerability in dosfstools, a collection of utilities for making and checking MS-DOS FAT filesystems. For Debian 8 "Jessie", these problems have been fixed in version 3.0.27-1+deb8u1. We recommend that you upgrade your dosfstools packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian 8 receives a vital update from Dosfstools addressing severe memory and overflow vulnerabilities identified in the latest releases.. dosfstools, security update, memory overflow, Debian LTS, vulnerability management. . Severity: Critical. LinuxSecurity.com Team
dosfstools could be made to crash or run programs if it processed a specially crafted filesystem.. =========================================================================Ubuntu Security Notice USN-2986-1 May 31, 2016 dosfstools vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 15.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: dosfstools could be made to crash or run programs if it processed a specially crafted filesystem. Software Description: - dosfstools: utilities for making and checking MS-DOS FAT filesystems Details: Hanno Böck discovered that dosfstools incorrectly handled certain malformed filesystems. A local attacker could use this issue to cause dosfstools to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: dosfstools 3.0.28-2ubuntu0.1 Ubuntu 15.10: dosfstools 3.0.28-1ubuntu0.1 Ubuntu 14.04 LTS: dosfstools 3.0.26-1ubuntu0.1 Ubuntu 12.04 LTS: dosfstools 3.0.12-1ubuntu1.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2986-1 CVE-2015-8872, CVE-2016-4804 Package Information: https://launchpad.net/ubuntu/+source/dosfstools/3.0.28-2ubuntu0.1 https://launchpad.net/ubuntu/+source/dosfstools/3.0.28-1ubuntu0.1 https://launchpad.net/ubuntu/+source/dosfstools/3.0.26-1ubuntu0.1 https://launchpad.net/ubuntu/+source/dosfstools/3.0.12-1ubuntu1.3 . A critical flaw in dosfstools affects multiple versions of Ubuntu, potentially leading to system failures or the execution of unintended software.. dosfstools vulnerabilities, denial of service attacks, ubuntu securityupdates. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.