Description
An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1724-1 | ntfs-3g security update |
Debian DSA |
DSA-4413-1 | ntfs-3g security update |
EUVD |
EUVD-2019-19118 | An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges. |
Ubuntu USN |
USN-3914-1 | NTFS-3G vulnerability |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:01:54.178Z
Reserved: 2019-03-13T00:00:00.000Z
Link: CVE-2019-9755
No data.
Status : Modified
Published: 2019-06-05T15:29:03.920
Modified: 2024-11-21T04:52:14.810
Link: CVE-2019-9755
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN