First published: Thu Jun 13 2024(Updated: )
NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ntfs-3g | <75dcdc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-52890 has a moderate severity due to the potential for a use-after-free vulnerability.
To mitigate CVE-2023-52890, upgrade to a version of Tuxera NTFS-3G greater than 75dcdc2.
CVE-2023-52890 is caused by a use-after-free condition in the ntfs_uppercase_mbs function within NTFS-3G.
Exploitation of CVE-2023-52890 is considered challenging, according to discussions in the CVE report.
All versions of Tuxera NTFS-3G prior to version 75dcdc2 are affected by CVE-2023-52890.