Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
203

Mageia: 2022-0385 Moderate: Ntfs-3g Buffer Overflow Risk

ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. (CVE-2021-46790) An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G . MGASA-2022-0385 - Updated ntfs-3g packages fix security vulnerability Publication date: 23 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0385.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-46790, CVE-2022-30783, CVE-2022-30784, CVE-2022-30785, CVE-2022-30786, CVE-2022-30787, CVE-2022-30788, CVE-2022-30789 ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. (CVE-2021-46790) An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite. (CVE-2022-30783) A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22. (CVE-2022-30784) A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite. (CVE-2022-30785) A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22. (CVE-2022-30786) An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite. (CVE-2022-30787) A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22. (CVE-2022-30788) A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22. (CVE-2022-30789) References: - https://bugs.mageia.org/show_bug.cgi?id=30479 - https://www.openwall.com/lists/oss-security/2022/05/26/1 - https://www.openwall.com/lists/oss-security/2022/05/26/2 - https://ubuntu.com/security/notices/USN-5452-1 -https://www.openwall.com/lists/oss-security/2022/06/07/4 - https://ubuntu.com/security/notices/USN-5463-1 - https://lists.debian.org/debian-security-announce/2022/msg00128.html - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/7JPX6OUCQKZX4PN5DQPVDUFZCOOZUX7Z/ - - https://www.cve.org/CVERecord?id=CVE-2021-46790 - https://www.cve.org/CVERecord?id=CVE-2022-30783 - https://www.cve.org/CVERecord?id=CVE-2022-30784 - https://www.cve.org/CVERecord?id=CVE-2022-30785 - https://www.cve.org/CVERecord?id=CVE-2022-30786 - https://www.cve.org/CVERecord?id=CVE-2022-30787 - https://www.cve.org/CVERecord?id=CVE-2022-30788 - https://www.cve.org/CVERecord?id=CVE-2022-30789 SRPMS: - 8/core/ntfs-3g-2021.8.22-1.1.mga8 . Recent ntfs-3g updates in Mageia rectify several security flaws linked to buffer overflows and the potential for protocol interception.. Mageia Security Update, NTFS-3G Buffer Overflow, Memory Issues. . LinuxSecurity.com Team

Calendar 2 Oct 23, 2022 Mageia
172

Ubuntu 16.04 ESM: USN-5463-2 Moderate: ntfs-3g Denial Of Service

Several security issues were fixed in ntfs-3g.. =========================================================================Ubuntu Security Notice USN-5463-2 August 02, 2022 ntfs-3g vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: Several security issues were fixed in ntfs-3g. Software Description: - ntfs-3g: read/write NTFS driver for FUSE Details: USN-5463-1 fixed vulnerabilities in NTFS-3G. This update provides the corresponding updates for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: Roman Fiedler discovered that NTFS-3G incorrectly handled certain return codes. A local attacker could possibly use this issue to intercept protocol traffic between FUSE and the kernel. (CVE-2022-30783) It was discovered that NTFS-3G incorrectly handled certain NTFS disk images. If a user or automated system were tricked into mounting a specially crafted disk image, a remote attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2022-30784, CVE-2022-30786, CVE-2022-30788, CVE-2022-30789) Roman Fiedler discovered that NTFS-3G incorrectly handled certain file handles. A local attacker could possibly use this issue to read and write arbitrary memory. (CVE-2022-30785, CVE-2022-30787) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: ntfs-3g 1:2015.3.14AR.1-1ubuntu0.3+esm3 Ubuntu 14.04 ESM: ntfs-3g 1:2013.1.13AR.1-2ubuntu2+esm3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5463-2 https://ubuntu.com/security/notices/USN-5463-1 CVE-2022-30783, CVE-2022-30784, CVE-2022-30785, CVE-2022-30786, CVE-2022-30787, CVE-2022-30788, CVE-2022-30789 . Multiple vulnerabilities have been addressed in ntfs-3g for Ubuntu 14.04 and 16.04 ESM. It is strongly advised to apply these critical updates.. ntfs-3g Fixes, Ubuntu Security Advisory, System Update Recommendations. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 02, 2022 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here