Bugzilla – Bug 1216701
VUL-0: CVE-2023-45897: exfatprogs: several out-of-bounds memory access
Last modified: 2023-11-24 13:55:59 UTC
exfatprogs before 1.2.2 allows out-of-bounds memory access, such as in read_file_dentry_set. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-45897 https://github.com/exfatprogs/exfatprogs/commit/4abc55e976573991e6a1117bb2b3711e59da07ae https://github.com/exfatprogs/exfatprogs/commit/22d0e43e8d24119cbfc6efafabb0dec6517a86c4 https://github.com/exfatprogs/exfatprogs/commit/ec78688e5fb5a70e13df82b4c0da1e6228d3ccdf#
Affected: - SUSE:SLE-15-SP3:Update - openSUSE:Factory
Only ec78688e5fb5a70e13df82b4c0da1e6228d3ccdf is relevant. exfat2img tool is not available and fsck did not handle dot-dot in this version.
SUSE-SU-2023:4449-1: An update that solves one vulnerability can now be installed. Category: security (moderate) Bug References: 1216701 CVE References: CVE-2023-45897 Sources used: openSUSE Leap 15.5 (src): exfatprogs-1.0.4-150300.3.12.1 Basesystem Module 15-SP4 (src): exfatprogs-1.0.4-150300.3.12.1 Basesystem Module 15-SP5 (src): exfatprogs-1.0.4-150300.3.12.1 openSUSE Leap 15.3 (src): exfatprogs-1.0.4-150300.3.12.1 openSUSE Leap 15.4 (src): exfatprogs-1.0.4-150300.3.12.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.