ntfs-3g 1:2017.3.23AR.3-3ubuntu1.2 source package in Ubuntu

Changelog

ntfs-3g (1:2017.3.23AR.3-3ubuntu1.2) focal-security; urgency=medium

  * SECURITY UPDATE: heap buffer overflow in ntfsck
    - debian/patches/CVE-2021-46790.patch: properly handle error in
      ntfsprogs/ntfsck.c.
    - CVE-2021-46790
  * SECURITY UPDATE: traffic interception via incorrect return code
    - debian/patches/CVE-2022-30783.patch: return proper error code in
      libfuse-lite/mount.c, src/ntfs-3g_common.c, src/ntfs-3g_common.h.
    - CVE-2022-30783
  * SECURITY UPDATE: heap exhaustion via invalid NTFS image
    - debian/patches/CVE-2022-30784.patch: Avoid allocating and reading an
      attribute beyond its full size in libntfs-3g/attrib.c.
    - CVE-2022-30784
  * SECURITY UPDATE: arbitrary memory access via fuse
    - debian/patches/CVE-2022-30785_30787.patch: check directory offset in
      libfuse-lite/fuse.c.
    - CVE-2022-30785
    - CVE-2022-30787
  * SECURITY UPDATE: heap overflow via ntfs attribute names
    - debian/patches/CVE-2022-30786-1.patch: make sure there is no null
      character in an attribute name in libntfs-3g/attrib.c.
    - debian/patches/CVE-2022-30786-2.patch: make sure there is no null
      character in an attribute name in libntfs-3g/attrib.c.
    - CVE-2022-30786
  * SECURITY UPDATE: heap buffer overflow via crafted NTFS image
    - debian/patches/CVE-2022-30788-1.patch: use a default usn when the
      former one cannot be retrieved in libntfs-3g/mft.c.
    - debian/patches/CVE-2022-30788-2.patch: fix operation on little endian
      data in libntfs-3g/mft.c.
    - CVE-2022-30788
  * SECURITY UPDATE: heap buffer overflow via crafted NTFS image
    - debian/patches/CVE-2022-30789.patch: make sure the client log data
      does not overflow from restart page in libntfs-3g/logfile.c.
    - CVE-2022-30789

 -- Marc Deslauriers <email address hidden>  Mon, 06 Jun 2022 14:09:42 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
linux-any kfreebsd-any
Section:
otherosfs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
ntfs-3g_2017.3.23AR.3.orig.tar.gz 1.2 MiB a83fbd533259abd5b73dc37635cc003a697248375702ddcc39af129957a7564b
ntfs-3g_2017.3.23AR.3-3ubuntu1.2.debian.tar.xz 40.4 KiB d719d0b8537f4437d5e795b346e6e36b8910e6bac0312d17143f11a7f0853271
ntfs-3g_2017.3.23AR.3-3ubuntu1.2.dsc 2.2 KiB 8d2452c1bd5b07b40453d95cd8e8e09062455630c9ee345a863a8a283e3ce020

View changes file

Binary packages built by this source

libntfs-3g883: read/write NTFS driver for FUSE (runtime library)

 NTFS-3G uses FUSE (Filesystem in Userspace) to provide support for the NTFS
 filesystem used by Microsoft Windows.
 .
 This package contains the actual library.

libntfs-3g883-dbgsym: debug symbols for libntfs-3g883
ntfs-3g: read/write NTFS driver for FUSE

 NTFS-3G uses FUSE (Filesystem in Userspace) to provide support for the NTFS
 filesystem used by Microsoft Windows.

ntfs-3g-dbgsym: debug symbols for ntfs-3g
ntfs-3g-dev: read/write NTFS driver for FUSE (development)

 NTFS-3G uses FUSE (Filesystem in Userspace) to provide support for the NTFS
 filesystem used by Microsoft Windows.
 .
 This package contains the development files.

ntfs-3g-dev-dbgsym: debug symbols for ntfs-3g-dev
ntfs-3g-udeb: read/write NTFS driver for FUSE