CVE-2023-5368

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/10/2023
Last modified:
29/11/2023

Description

On an msdosfs filesystem, the &amp;#39;truncate&amp;#39; or &amp;#39;ftruncate&amp;#39; system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes.<br /> <br /> This may permit a user with write access to files on a msdosfs filesystem to read unintended data (e.g. from a previously deleted file).<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* 12.4 (excluding)
cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* 13.0 (including) 13.2 (excluding)
cpe:2.3:o:freebsd:freebsd:12.4:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.4:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.4:p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.4:p3:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.4:p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.4:p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.2:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.2:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.2:p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.2:p3:*:*:*:*:*:*