ntfs-3g 1:2017.3.23AR.3-3ubuntu5.1 source package in Ubuntu

Changelog

ntfs-3g (1:2017.3.23AR.3-3ubuntu5.1) impish-security; urgency=medium

  * SECURITY UPDATE: heap buffer overflow in ntfsck
    - debian/patches/CVE-2021-46790.patch: properly handle error in
      ntfsprogs/ntfsck.c.
    - CVE-2021-46790
  * SECURITY UPDATE: traffic interception via incorrect return code
    - debian/patches/CVE-2022-30783.patch: return proper error code in
      libfuse-lite/mount.c, src/ntfs-3g_common.c, src/ntfs-3g_common.h.
    - CVE-2022-30783
  * SECURITY UPDATE: heap exhaustion via invalid NTFS image
    - debian/patches/CVE-2022-30784.patch: Avoid allocating and reading an
      attribute beyond its full size in libntfs-3g/attrib.c.
    - CVE-2022-30784
  * SECURITY UPDATE: arbitrary memory access via fuse
    - debian/patches/CVE-2022-30785_30787.patch: check directory offset in
      libfuse-lite/fuse.c.
    - CVE-2022-30785
    - CVE-2022-30787
  * SECURITY UPDATE: heap overflow via ntfs attribute names
    - debian/patches/CVE-2022-30786-1.patch: make sure there is no null
      character in an attribute name in libntfs-3g/attrib.c.
    - debian/patches/CVE-2022-30786-2.patch: make sure there is no null
      character in an attribute name in libntfs-3g/attrib.c.
    - CVE-2022-30786
  * SECURITY UPDATE: heap buffer overflow via crafted NTFS image
    - debian/patches/CVE-2022-30788-1.patch: use a default usn when the
      former one cannot be retrieved in libntfs-3g/mft.c.
    - debian/patches/CVE-2022-30788-2.patch: fix operation on little endian
      data in libntfs-3g/mft.c.
    - CVE-2022-30788
  * SECURITY UPDATE: heap buffer overflow via crafted NTFS image
    - debian/patches/CVE-2022-30789.patch: make sure the client log data
      does not overflow from restart page in libntfs-3g/logfile.c.
    - CVE-2022-30789

 -- Marc Deslauriers <email address hidden>  Mon, 06 Jun 2022 14:08:38 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Impish
Original maintainer:
Ubuntu Developers
Architectures:
linux-any kfreebsd-any
Section:
otherosfs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
ntfs-3g_2017.3.23AR.3.orig.tar.gz 1.2 MiB a83fbd533259abd5b73dc37635cc003a697248375702ddcc39af129957a7564b
ntfs-3g_2017.3.23AR.3-3ubuntu5.1.debian.tar.xz 40.6 KiB d69ccf973f330c67f9884a016499bba992daeb9975f14f8c9740e2aee2bd9766
ntfs-3g_2017.3.23AR.3-3ubuntu5.1.dsc 2.2 KiB f3a9f57148599b3b29754b1af4c7709eb3252dd4c316db495f1a818e604367e8

View changes file

Binary packages built by this source

libntfs-3g883: No summary available for libntfs-3g883 in ubuntu impish.

No description available for libntfs-3g883 in ubuntu impish.

libntfs-3g883-dbgsym: No summary available for libntfs-3g883-dbgsym in ubuntu impish.

No description available for libntfs-3g883-dbgsym in ubuntu impish.

ntfs-3g: No summary available for ntfs-3g in ubuntu impish.

No description available for ntfs-3g in ubuntu impish.

ntfs-3g-dbgsym: No summary available for ntfs-3g-dbgsym in ubuntu impish.

No description available for ntfs-3g-dbgsym in ubuntu impish.

ntfs-3g-dev: No summary available for ntfs-3g-dev in ubuntu impish.

No description available for ntfs-3g-dev in ubuntu impish.

ntfs-3g-dev-dbgsym: No summary available for ntfs-3g-dev-dbgsym in ubuntu impish.

No description available for ntfs-3g-dev-dbgsym in ubuntu impish.