ntfs-3g 1:2021.8.22-3ubuntu1.1 source package in Ubuntu

Changelog

ntfs-3g (1:2021.8.22-3ubuntu1.1) jammy-security; urgency=medium

  * SECURITY UPDATE: heap buffer overflow in ntfsck
    - debian/patches/CVE-2021-46790.patch: properly handle error in
      ntfsprogs/ntfsck.c.
    - CVE-2021-46790
  * SECURITY UPDATE: traffic interception via incorrect return code
    - debian/patches/CVE-2022-30783.patch: return proper error code in
      libfuse-lite/mount.c, src/ntfs-3g_common.c, src/ntfs-3g_common.h.
    - CVE-2022-30783
  * SECURITY UPDATE: heap exhaustion via invalid NTFS image
    - debian/patches/CVE-2022-30784.patch: Avoid allocating and reading an
      attribute beyond its full size in libntfs-3g/attrib.c.
    - CVE-2022-30784
  * SECURITY UPDATE: arbitrary memory access via fuse
    - debian/patches/CVE-2022-30785_30787.patch: check directory offset in
      libfuse-lite/fuse.c.
    - CVE-2022-30785
    - CVE-2022-30787
  * SECURITY UPDATE: heap overflow via ntfs attribute names
    - debian/patches/CVE-2022-30786-1.patch: make sure there is no null
      character in an attribute name in libntfs-3g/attrib.c.
    - debian/patches/CVE-2022-30786-2.patch: make sure there is no null
      character in an attribute name in libntfs-3g/attrib.c.
    - CVE-2022-30786
  * SECURITY UPDATE: heap buffer overflow via crafted NTFS image
    - debian/patches/CVE-2022-30788-1.patch: use a default usn when the
      former one cannot be retrieved in libntfs-3g/mft.c.
    - debian/patches/CVE-2022-30788-2.patch: fix operation on little endian
      data in libntfs-3g/mft.c.
    - CVE-2022-30788
  * SECURITY UPDATE: heap buffer overflow via crafted NTFS image
    - debian/patches/CVE-2022-30789.patch: make sure the client log data
      does not overflow from restart page in libntfs-3g/logfile.c.
    - CVE-2022-30789

 -- Marc Deslauriers <email address hidden>  Mon, 06 Jun 2022 13:57:00 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Jammy
Original maintainer:
Ubuntu Developers
Architectures:
linux-any kfreebsd-any
Section:
otherosfs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
ntfs-3g_2021.8.22.orig.tar.gz 878.4 KiB 5cb9fa93bf2b9685e3f1b598861f6082786e76562989a5752c7379dbe0e989a2
ntfs-3g_2021.8.22-3ubuntu1.1.debian.tar.xz 34.7 KiB 8ee91f8ad2f8f3b6a9700491608eb835f6ecbdf01a25ae46c6cf345965825ef5
ntfs-3g_2021.8.22-3ubuntu1.1.dsc 2.2 KiB 250ed37dfdf98e7b919e8548e88586c64879693223df86332ceb3c993294bac9

View changes file

Binary packages built by this source

libntfs-3g89: read/write NTFS driver for FUSE (runtime library)

 NTFS-3G uses FUSE (Filesystem in Userspace) to provide support for the NTFS
 filesystem used by Microsoft Windows.
 .
 This package contains the actual library.

libntfs-3g89-dbgsym: debug symbols for libntfs-3g89
ntfs-3g: read/write NTFS driver for FUSE

 NTFS-3G uses FUSE (Filesystem in Userspace) to provide support for the NTFS
 filesystem used by Microsoft Windows.

ntfs-3g-dbgsym: debug symbols for ntfs-3g
ntfs-3g-dev: read/write NTFS driver for FUSE (development)

 NTFS-3G uses FUSE (Filesystem in Userspace) to provide support for the NTFS
 filesystem used by Microsoft Windows.
 .
 This package contains the development files.

ntfs-3g-dev-dbgsym: debug symbols for ntfs-3g-dev