package/ntfs-3g: add upstream security fix for CVE-2019-9755
authorPeter Korsgaard <peter@korsgaard.com>
Tue, 4 Feb 2020 15:50:31 +0000 (16:50 +0100)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Tue, 4 Feb 2020 22:13:07 +0000 (23:13 +0100)
commit4fb3c69854b01fd8f6483a8dbbb73d05ef26e96a
tree935ee24ec92f5d52e5dda5b0b13b15cb245fad46
parent615b7c4af59229a14a52f789ce4692dea1828ba3
package/ntfs-3g: add upstream security fix for CVE-2019-9755

Fixes CVE-2019-9755: An integer underflow issue exists in ntfs-3g 2017.3.23.
A local attacker could potentially exploit this by running /bin/ntfs-3g with
specially crafted arguments from a specially crafted directory to cause a
heap buffer overflow, resulting in a crash or the ability to execute
arbitrary code.  In installations where /bin/ntfs-3g is a setuid-root
binary, this could lead to a local escalation of privileges.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/ntfs-3g/0001-Fixed-reporting-an-error-when-failed-to-build-the-mo.patch [new file with mode: 0644]