First published: Mon Aug 10 2020(Updated: )
An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code execution. An attacker can provide a malicious file to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Array-tools | =1.12.0 | |
Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6070 is classified as a high severity vulnerability due to the potential for code execution.
To mitigate CVE-2020-6070, upgrading to the latest version of f2fs-tools beyond 1.12.0 is recommended.
CVE-2020-6070 affects f2fs-tools version 1.12.0 and Fedora version 33.
Any attacker who can provide a specially crafted f2fs file can potentially exploit CVE-2020-6070.
If vulnerable to CVE-2020-6070, an attacker could execute arbitrary code on the affected system.