CVE-2016-4804

Published on: 06/03/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:26:59 PM UTC

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Certain versions of Ubuntu Linux from Canonical contain the following vulnerability:

The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function.

  • CVE-2016-4804 has been assigned by [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 6.2 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
LOCAL LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE NONE HIGH

CVSS2 Score: 2.1 - LOW

Access
Vector
Access
Complexity
Authentication
LOCAL LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE NONE PARTIAL

CVE References

Description Tags Link
Heap overflow in function read_fat() · Issue #25 · dosfstools/dosfstools · GitHub Patch
Vendor Advisory
github.com
text/html
URL Logo CONFIRM github.com/dosfstools/dosfstools/issues/25
read_boot(): Handle excessive FAT size specifications · dosfstools/[email protected] · GitHub github.com
text/html
URL Logo CONFIRM github.com/dosfstools/dosfstools/commit/e8eff147e9da1185f9afd5b25948153a3b97cf52
USN-2986-1: dosfstools vulnerabilities | Ubuntu www.ubuntu.com
text/html
URL Logo UBUNTU USN-2986-1
heap out of bounds read in get_fat() · Issue #26 · dosfstools/dosfstools · GitHub Patch
Vendor Advisory
github.com
text/html
URL Logo CONFIRM github.com/dosfstools/dosfstools/issues/26
[SECURITY] [DLA 2224-1] dosfstools security update lists.debian.org
text/html
URL Logo MLIST [debian-lts-announce] 20200530 [SECURITY] [DLA 2224-1] dosfstools security update
openSUSE-SU-2016:2233-1: moderate: Security update for dosfstools lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:2233
openSUSE-SU-2016:1461-1: moderate: Security update for dosfstools lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:1461
dosfstools Multiple Security Vulnerabilities cve.report (archive)
text/html
URL Logo BID 90311
dosfstools / fsck.vfat: Several invalid memory accesses | The Fuzzing Project Patch
blog.fuzzing-project.org
text/html
URL Logo MISC blog.fuzzing-project.org/44-dosfstools-fsck.vfat-Several-invalid-memory-accesses.html

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Operating
System
CanonicalUbuntu Linux12.04AllAllAll
Operating
System
CanonicalUbuntu Linux14.04AllAllAll
Operating
System
CanonicalUbuntu Linux15.10AllAllAll
Operating
System
CanonicalUbuntu Linux16.04AllAllAll
Operating
System
CanonicalUbuntu Linux12.04AllAllAll
Operating
System
CanonicalUbuntu Linux14.04AllAllAll
Operating
System
CanonicalUbuntu Linux15.10AllAllAll
Operating
System
CanonicalUbuntu Linux16.04AllAllAll
ApplicationDosfstools ProjectDosfstoolsAllAllAllAll
Operating
System
OpensuseLeap42.1AllAllAll
Operating
System
OpensuseLeap42.1AllAllAll
Operating
System
OpensuseOpensuse13.2AllAllAll
Operating
System
OpensuseOpensuse13.2AllAllAll
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*:
  • cpe:2.3:a:dosfstools_project:dosfstools:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*:
  • cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*:
  • cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*:
  • cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*: