Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-33285

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted ntfs partition. The root cause is a missing consistency check after reading an MFT record : the "bytes_in_use" field should be less than the "bytes_allocated" field. When it is not, the parsing of the records proceeds into the wild.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.4%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.9
References
Products affected by CVE-2021-33285
  • Tuxera » Ntfs-3g » Version: N/A
    cpe:2.3:a:tuxera:ntfs-3g:-
  • Tuxera » Ntfs-3g » Version: 2009.1.1
    cpe:2.3:a:tuxera:ntfs-3g:2009.1.1
  • Tuxera » Ntfs-3g » Version: 2009.11.14
    cpe:2.3:a:tuxera:ntfs-3g:2009.11.14
  • Tuxera » Ntfs-3g » Version: 2009.2.1
    cpe:2.3:a:tuxera:ntfs-3g:2009.2.1
  • Tuxera » Ntfs-3g » Version: 2009.3.8
    cpe:2.3:a:tuxera:ntfs-3g:2009.3.8
  • Tuxera » Ntfs-3g » Version: 2009.4.4
    cpe:2.3:a:tuxera:ntfs-3g:2009.4.4
  • Tuxera » Ntfs-3g » Version: 2010.1.16
    cpe:2.3:a:tuxera:ntfs-3g:2010.1.16
  • Tuxera » Ntfs-3g » Version: 2010.10.2
    cpe:2.3:a:tuxera:ntfs-3g:2010.10.2
  • Tuxera » Ntfs-3g » Version: 2010.3.6
    cpe:2.3:a:tuxera:ntfs-3g:2010.3.6
  • Tuxera » Ntfs-3g » Version: 2010.5.16
    cpe:2.3:a:tuxera:ntfs-3g:2010.5.16
  • Tuxera » Ntfs-3g » Version: 2010.5.22
    cpe:2.3:a:tuxera:ntfs-3g:2010.5.22
  • Tuxera » Ntfs-3g » Version: 2010.8.8
    cpe:2.3:a:tuxera:ntfs-3g:2010.8.8
  • Tuxera » Ntfs-3g » Version: 2011.1.15
    cpe:2.3:a:tuxera:ntfs-3g:2011.1.15
  • Tuxera » Ntfs-3g » Version: 2011.4.12
    cpe:2.3:a:tuxera:ntfs-3g:2011.4.12
  • Tuxera » Ntfs-3g » Version: 2012.1.15
    cpe:2.3:a:tuxera:ntfs-3g:2012.1.15
  • Tuxera » Ntfs-3g » Version: 2013.1.13
    cpe:2.3:a:tuxera:ntfs-3g:2013.1.13
  • Tuxera » Ntfs-3g » Version: 2014.2.15
    cpe:2.3:a:tuxera:ntfs-3g:2014.2.15
  • Tuxera » Ntfs-3g » Version: 2015.3.14
    cpe:2.3:a:tuxera:ntfs-3g:2015.3.14
  • Tuxera » Ntfs-3g » Version: 2016.2.22
    cpe:2.3:a:tuxera:ntfs-3g:2016.2.22
  • Tuxera » Ntfs-3g » Version: 2017.3.23
    cpe:2.3:a:tuxera:ntfs-3g:2017.3.23
  • Debian » Debian Linux » Version: 10.0
    cpe:2.3:o:debian:debian_linux:10.0
  • Debian » Debian Linux » Version: 11.0
    cpe:2.3:o:debian:debian_linux:11.0
  • Debian » Debian Linux » Version: 9.0
    cpe:2.3:o:debian:debian_linux:9.0
  • Fedoraproject » Fedora » Version: 33
    cpe:2.3:o:fedoraproject:fedora:33
  • Fedoraproject » Fedora » Version: 34
    cpe:2.3:o:fedoraproject:fedora:34
  • Fedoraproject » Fedora » Version: 35
    cpe:2.3:o:fedoraproject:fedora:35
  • Redhat » Enterprise Linux » Version: 7.0
    cpe:2.3:o:redhat:enterprise_linux:7.0
  • Redhat » Enterprise Linux » Version: 8.0
    cpe:2.3:o:redhat:enterprise_linux:8.0


Contact Us

Shodan ® - All rights reserved