CVE-2021-46790: Buffer Overflow
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+5123-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-46790.
What is the severity of CVE-2021-46790?
The severity of CVE-2021-46790 is high with a severity value of 7.8.
Which software is affected by CVE-2021-46790?
NTFS-3G versions up to 2021.8.22, Tuxera Ntfs-3g, Debian Linux versions 10.0 and 11.0, and Fedora versions 35 and 36 are affected by CVE-2021-46790.
What is the recommended remedy for CVE-2021-46790?
The recommended remedy for CVE-2021-46790 is to update to version 2022.10.3-1 of the ntfs-3g package for Debian Linux, and to update to version 2022.5.17 or later for Fedora.
Where can I find more information about CVE-2021-46790?
You can find more information about CVE-2021-46790 at the following references: [CVE-2021-46790](https://security-tracker.debian.org/tracker/CVE-2021-46790), [CVE-2022-30783](https://security-tracker.debian.org/tracker/CVE-2022-30783), [CVE-2022-30784](https://security-tracker.debian.org/tracker/CVE-2022-30784).