ALT-BU-2022-7189-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-10-09
CVE-2022-3857
Rejected reason: Maintainer contacted. This is a false-positive. The flaw does not actually exist and was erroneously tested.
Closed vulnerabilities
BDU:2022-03378
Уязвимость функции ntfs_get_attribute_value файловой системы NTFS для модуля FUSE NTFS-3G, позволяющая нарушителю выполнить произвольный код с повышенными привилегиями
BDU:2022-03700
Уязвимость функции ntfs_names_full_collate файловой системы NTFS для модуля FUSE NTFS-3G, позволяющая нарушителю выполнить произвольный код с повышенными привилегиями
BDU:2022-03701
Уязвимость функции ntfs_mft_rec_alloc файловой системы NTFS для модуля FUSE NTFS-3G, позволяющая нарушителю выполнить произвольный код с повышенными привилегиями
BDU:2022-03707
Уязвимость функции ntfs_check_log_client_array файловой системы NTFS для модуля FUSE NTFS-3G, позволяющая нарушителю выполнить произвольный код с повышенными привилегиями
BDU:2022-03917
Уязвимость функции check_file_record файловой системы NTFS для модуля FUSE NTFS-3G, позволяющая нарушителю выполнить произвольный код с повышенными привилегиями
BDU:2022-03919
Уязвимость функции fuse_kern_mount библиотеки libfuse-lite файловой системы NTFS для модуля FUSE NTFS-3G, позволяющая нарушителю выполнить произвольный код с повышенными привилегиями
BDU:2022-03924
Уязвимость функции fuse_lib_readdir библиотеки libfuse-lite файловой системы NTFS для модуля FUSE NTFS-3G, позволяющая нарушителю выполнить произвольный код с повышенными привилегиями
BDU:2022-03951
Уязвимость дескриптора файлов файловой системы NTFS для модуля FUSE NTFS-3G, позволяющая нарушителю выполнить произвольный код с повышенными привилегиями
BDU:2022-06607
Уязвимость утилиты ntfs-3g набора драйверов NTFS-3G реализации файловой системы NTFS, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2021-46790
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.
- [oss-security] 20220526 OPEN SOURCE NTFS-3G SECURITY ADVISORY NTFS3G-SA-2022-0001
- [oss-security] 20220526 OPEN SOURCE NTFS-3G SECURITY ADVISORY NTFS3G-SA-2022-0001
- https://github.com/tuxera/ntfs-3g/issues/16
- https://github.com/tuxera/ntfs-3g/issues/16
- FEDORA-2022-8f775872c9
- FEDORA-2022-8f775872c9
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-1176b501f0
- FEDORA-2022-1176b501f0
- DSA-5160
- DSA-5160
Modified: 2024-11-21
CVE-2022-30783
An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite.
- [oss-security] 20220607 UNPAR-2022-0 Multiple Vulnerabilities in ntfs-3g NTFS Mount Tool
- [oss-security] 20220607 UNPAR-2022-0 Multiple Vulnerabilities in ntfs-3g NTFS Mount Tool
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-6mv4-4v73-xw58
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-6mv4-4v73-xw58
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- FEDORA-2022-8f775872c9
- FEDORA-2022-8f775872c9
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-1176b501f0
- FEDORA-2022-1176b501f0
- GLSA-202301-01
- GLSA-202301-01
- DSA-5160
- DSA-5160
Modified: 2024-11-21
CVE-2022-30784
A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4x
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4x
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- FEDORA-2022-8f775872c9
- FEDORA-2022-8f775872c9
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-1176b501f0
- FEDORA-2022-1176b501f0
- GLSA-202301-01
- GLSA-202301-01
- DSA-5160
- DSA-5160
Modified: 2024-11-21
CVE-2022-30785
A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
- [oss-security] 20220607 UNPAR-2022-0 Multiple Vulnerabilities in ntfs-3g NTFS Mount Tool
- [oss-security] 20220607 UNPAR-2022-0 Multiple Vulnerabilities in ntfs-3g NTFS Mount Tool
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-6mv4-4v73-xw58
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-6mv4-4v73-xw58
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- FEDORA-2022-8f775872c9
- FEDORA-2022-8f775872c9
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-1176b501f0
- FEDORA-2022-1176b501f0
- GLSA-202301-01
- GLSA-202301-01
- DSA-5160
- DSA-5160
Modified: 2024-11-21
CVE-2022-30786
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4x
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4x
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- FEDORA-2022-8f775872c9
- FEDORA-2022-8f775872c9
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-1176b501f0
- FEDORA-2022-1176b501f0
- GLSA-202301-01
- GLSA-202301-01
- DSA-5160
- DSA-5160
Modified: 2024-11-21
CVE-2022-30787
An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
- [oss-security] 20220607 UNPAR-2022-0 Multiple Vulnerabilities in ntfs-3g NTFS Mount Tool
- [oss-security] 20220607 UNPAR-2022-0 Multiple Vulnerabilities in ntfs-3g NTFS Mount Tool
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-6mv4-4v73-xw58
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-6mv4-4v73-xw58
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- FEDORA-2022-8f775872c9
- FEDORA-2022-8f775872c9
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-1176b501f0
- FEDORA-2022-1176b501f0
- GLSA-202301-01
- GLSA-202301-01
- DSA-5160
- DSA-5160
Modified: 2024-11-21
CVE-2022-30788
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4x
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4x
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- FEDORA-2022-8f775872c9
- FEDORA-2022-8f775872c9
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-1176b501f0
- FEDORA-2022-1176b501f0
- GLSA-202301-01
- GLSA-202301-01
- DSA-5160
- DSA-5160
Modified: 2024-11-21
CVE-2022-30789
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4x
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4x
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- [debian-lts-announce] 20220621 [SECURITY] [DLA 3055-1] ntfs-3g security update
- FEDORA-2022-8f775872c9
- FEDORA-2022-8f775872c9
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-13bc8c91b0
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-8fa7e5aeaf
- FEDORA-2022-1176b501f0
- FEDORA-2022-1176b501f0
- GLSA-202301-01
- GLSA-202301-01
- DSA-5160
- DSA-5160
Modified: 2024-11-21
CVE-2022-40284
A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.
- http://www.openwall.com/lists/oss-security/2022/10/31/2
- http://www.openwall.com/lists/oss-security/2022/10/31/2
- https://github.com/tuxera/ntfs-3g/releases
- https://github.com/tuxera/ntfs-3g/releases
- [debian-lts-announce] 20221121 [SECURITY] [DLA 3201-1] ntfs-3g security update
- [debian-lts-announce] 20221121 [SECURITY] [DLA 3201-1] ntfs-3g security update
- FEDORA-2022-14f11bfc73
- FEDORA-2022-14f11bfc73
- FEDORA-2022-4915124227
- FEDORA-2022-4915124227
- FEDORA-2022-243616c548
- FEDORA-2022-243616c548
- GLSA-202301-01
- GLSA-202301-01
Closed bugs
Сломалась загрузка с отдельным /usr
Closed vulnerabilities
BDU:2022-06821
Уязвимость реализации параметра --inspect программного средства работы с объектами Node.js, позволяющей нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2022-43548
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.
- [debian-lts-announce] 20230226 [SECURITY] [DLA 3344-1] nodejs security update
- [debian-lts-announce] 20230226 [SECURITY] [DLA 3344-1] nodejs security update
- https://nodejs.org/en/blog/vulnerability/november-2022-security-releases/
- https://nodejs.org/en/blog/vulnerability/november-2022-security-releases/
- https://security.netapp.com/advisory/ntap-20230120-0004/
- https://security.netapp.com/advisory/ntap-20230120-0004/
- https://security.netapp.com/advisory/ntap-20230427-0007/
- https://security.netapp.com/advisory/ntap-20230427-0007/
- DSA-5326
- DSA-5326