The libfsntfs_security_descriptor_values_free function in libfsntfs_security_descriptor_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause a denial of service (double-free) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libfsntfs | Libfsntfs_project | * | 20180420 (including) |
Libfsntfs | Ubuntu | artful | * |
Libfsntfs | Ubuntu | bionic | * |
Libfsntfs | Ubuntu | cosmic | * |
Libfsntfs | Ubuntu | xenial | * |