CVE-2015-8872

The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clusters to the third to last entry on a FAT12 filesystem, which triggers an "off-by-two error."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
VendorProductVersion
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
15.10
canonicalubuntu_linux
16.04
opensuseleap
42.1
opensuseopensuse
13.2
dosfstools_projectdosfstools
𝑥
≤ 3.0.28
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dosfstools
bookworm
4.2-1
fixed
bullseye
4.2-1
fixed
sid
4.2-1.1
fixed
trixie
4.2-1.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dosfstools
zesty
not-affected
yakkety
not-affected
xenial
Fixed 3.0.28-2ubuntu0.1
released
wily
Fixed 3.0.28-1ubuntu0.1
released
trusty
Fixed 3.0.26-1ubuntu0.1
released
precise
Fixed 3.0.12-1ubuntu1.3
released
Common Weakness Enumeration