Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2020-6108
HistoryOct 15, 2020 - 3:15 p.m.

CVE-2020-6108

2020-10-1515:15:00
Alpine Linux Development Team
security.alpinelinux.org
22
code execution
vulnerability
f2fs-tools

EPSS

0.001

Percentile

40.1%

An exploitable code execution vulnerability exists in the fsck_chk_orphan_node functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause a heap buffer overflow resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability.

OSVersionArchitecturePackageVersionFilename
Alpine3.12-mainnoarchf2fs-tools= 1.13.0-r0UNKNOWN
Alpine3.11-mainnoarchf2fs-tools= 1.13.0-r0UNKNOWN
Alpine3.10-mainnoarchf2fs-tools= 1.12.0-r0UNKNOWN

EPSS

0.001

Percentile

40.1%