Back

HIGH

ntfs-3g: heap-based buffer overflow leads to local root privilege escalation

Published Jun 5, 2019

Description

An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.

Affected products

Remediation

Red Hat statement

This flaw has a lower impact on Red Hat Enterprise Linux because the ntfs-3g tool is run in a supermin appliance, which is similar to a virtual machine instantiated on the fly, and it does not have the SUID bit set. Thus an attacker is very limited on what he can do to the vulnerable system.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 5, 2019
Updated Aug 4, 2024
Reserved Mar 13, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 21, 2019