5.5

CVE-2023-45897

Exploit
exfatprogs before 1.2.2 allows out-of-bounds memory access, such as in read_file_dentry_set.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NamjaejeonExfatprogs Version < 1.2.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.297
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://dfir.ru/2023/11/01/cve-2023-45897-a-vulnerability-in-the-linux-exfat-userspace-tools/
Third Party Advisory
Exploit
https://github.com/exfatprogs/exfatprogs/commit/22d0e43e8d24119cbfc6efafabb0dec6517a86c4
Patch
https://github.com/exfatprogs/exfatprogs/commit/4abc55e976573991e6a1117bb2b3711e59da07ae
Patch
https://github.com/exfatprogs/exfatprogs/commit/ec78688e5fb5a70e13df82b4c0da1e6228d3ccdf
Patch
https://github.com/exfatprogs/exfatprogs/releases/tag/1.2.2
Release Notes
https://lists.debian.org/debian-lts-announce/2024/09/msg00003.html