6.5

CVE-2023-5368

msdosfs data disclosure

On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes.

This may permit a user with write access to files on a msdosfs filesystem to read unintended data (e.g. from a previously deleted file).

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freebsd ≫ Freebsd Version < 12.4
Freebsd ≫ Freebsd Version >= 13.0 < 13.2
Freebsd ≫ Freebsd Version 12.4 Update -
Freebsd ≫ Freebsd Version 12.4 Update p1
Freebsd ≫ Freebsd Version 12.4 Update p2
Freebsd ≫ Freebsd Version 12.4 Update p3
Freebsd ≫ Freebsd Version 12.4 Update p4
Freebsd ≫ Freebsd Version 12.4 Update p5
Freebsd ≫ Freebsd Version 13.2 Update -
Freebsd ≫ Freebsd Version 13.2 Update p1
Freebsd ≫ Freebsd Version 13.2 Update p2
Freebsd ≫ Freebsd Version 13.2 Update p3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.54% 0.408
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-1188 Initialization of a Resource with an Insecure Default

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

https://dfir.ru/2023/11/01/bringing-unallocated-data-back-the-fat12-16-32-case/
https://security.FreeBSD.org/advisories/FreeBSD-SA-23:12.msdosfs.asc
Patch
https://security.netapp.com/advisory/ntap-20231124-0004/