USN-6970-1: exfatprogs vulnerability
Published Aug 20, 2024
·Updated
It was discovered that exfatprogs incorrectly handled certain memory operations. If a user or automated system were tricked into handling specially crafted exfat partitions, a remote attacker could use this issue to cause exfatprogs to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/exfatprogs<1.1.3-1ubuntu0.1
1.1.3-1ubuntu0.1
Ubuntu Ubuntu=22.04
Event History
Aug 20, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6970-1?
USN-6970-1 is classified as a low-severity vulnerability.
2
How do I fix USN-6970-1?
To fix USN-6970-1, upgrade to exfatprogs version 1.1.3-1ubuntu0.1 or later.
3
What could an attacker achieve with USN-6970-1?
An attacker could cause exfatprogs to crash, resulting in a denial of service.
4
Which versions of Ubuntu are affected by USN-6970-1?
USN-6970-1 affects Ubuntu 22.04 with exfatprogs versions earlier than 1.1.3-1ubuntu0.1.
5
Is USN-6970-1 a remote exploit?
Yes, USN-6970-1 can be exploited remotely if a specially crafted exfat partition is handled.