CVE-2023-5368
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/10/2023
Last modified:
29/11/2023
Description
On an msdosfs filesystem, the &#39;truncate&#39; or &#39;ftruncate&#39; system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes.<br />
<br />
This may permit a user with write access to files on a msdosfs filesystem to read unintended data (e.g. from a previously deleted file).<br />
<br />
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* | 12.4 (excluding) | |
| cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* | 13.0 (including) | 13.2 (excluding) |
| cpe:2.3:o:freebsd:freebsd:12.4:-:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:12.4:p1:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:12.4:p2:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:12.4:p3:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:12.4:p4:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:12.4:p5:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:13.2:-:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:13.2:p1:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:13.2:p2:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:13.2:p3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



