ALT-PU-2017-2316-1
Package dosfstools updated to version 4.1-alt0.M80C.1 for branch c8 in task 188759.
Closed vulnerabilities
Published: 2016-06-03
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2015-8872
The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clusters to the third to last entry on a FAT12 filesystem, which triggers an "off-by-two error."
Severity: MEDIUM (6.2)
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- openSUSE-SU-2016:1461
- openSUSE-SU-2016:1461
- openSUSE-SU-2016:2233
- openSUSE-SU-2016:2233
- 90311
- 90311
- USN-2986-1
- USN-2986-1
- https://blog.fuzzing-project.org/44-dosfstools-fsck.vfat-Several-invalid-memory-accesses.html
- https://blog.fuzzing-project.org/44-dosfstools-fsck.vfat-Several-invalid-memory-accesses.html
- https://github.com/dosfstools/dosfstools/commit/07908124838afcc99c577d1d3e84cef2dbd39cb7
- https://github.com/dosfstools/dosfstools/commit/07908124838afcc99c577d1d3e84cef2dbd39cb7
- https://github.com/dosfstools/dosfstools/issues/12
- https://github.com/dosfstools/dosfstools/issues/12
- https://github.com/dosfstools/dosfstools/releases/tag/v4.0
- https://github.com/dosfstools/dosfstools/releases/tag/v4.0
- [debian-lts-announce] 20200530 [SECURITY] [DLA 2224-1] dosfstools security update
- [debian-lts-announce] 20200530 [SECURITY] [DLA 2224-1] dosfstools security update
Published: 2016-06-03
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2016-4804
The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function.
Severity: MEDIUM (6.2)
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- openSUSE-SU-2016:1461
- openSUSE-SU-2016:1461
- openSUSE-SU-2016:2233
- openSUSE-SU-2016:2233
- 90311
- 90311
- USN-2986-1
- USN-2986-1
- https://blog.fuzzing-project.org/44-dosfstools-fsck.vfat-Several-invalid-memory-accesses.html
- https://blog.fuzzing-project.org/44-dosfstools-fsck.vfat-Several-invalid-memory-accesses.html
- https://github.com/dosfstools/dosfstools/commit/e8eff147e9da1185f9afd5b25948153a3b97cf52
- https://github.com/dosfstools/dosfstools/commit/e8eff147e9da1185f9afd5b25948153a3b97cf52
- https://github.com/dosfstools/dosfstools/issues/25
- https://github.com/dosfstools/dosfstools/issues/25
- https://github.com/dosfstools/dosfstools/issues/26
- https://github.com/dosfstools/dosfstools/issues/26
- [debian-lts-announce] 20200530 [SECURITY] [DLA 2224-1] dosfstools security update
- [debian-lts-announce] 20200530 [SECURITY] [DLA 2224-1] dosfstools security update