Lucene search

K
cvelistFreebsdCVELIST:CVE-2023-5368
HistoryOct 04, 2023 - 3:38 a.m.

CVE-2023-5368 msdosfs data disclosure

2023-10-0403:38:09
CWE-1188
freebsd
www.cve.org
msdosfs
filesystem
truncate
ftruncate
data disclosure
unintended data
deleted file
security vulnerability

0.001 Low

EPSS

Percentile

24.8%

On an msdosfs filesystem, the ‘truncate’ or ‘ftruncate’ system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes.

This may permit a user with write access to files on a msdosfs filesystem to read unintended data (e.g. from a previously deleted file).

CNA Affected

[
  {
    "defaultStatus": "unknown",
    "modules": [
      "msdosfs"
    ],
    "product": "FreeBSD",
    "vendor": "FreeBSD",
    "versions": [
      {
        "lessThan": "p4",
        "status": "affected",
        "version": "13.2-RELEASE",
        "versionType": "release"
      },
      {
        "lessThan": "p6",
        "status": "affected",
        "version": "12.4-RELEASE",
        "versionType": "release"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

24.8%

Related for CVELIST:CVE-2023-5368