The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clusters to the third to last entry on a FAT12 filesystem, which triggers an "off-by-two error."
CVSS Details
- CVSS 3.1 Base Score: 6.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dosfstools | Mar 31, 2017 | May 15, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade dosfstools | Dec 4, 2019 | Jun 3, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade dosfstools | Dec 18, 2019 | Jun 3, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade dosfstools | Sep 24, 2019 | Jun 3, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 14, 2016 |
| Suse | — | Upgrade dosfstools | Jun 3, 2016 | Jun 3, 2016 |
| Ubuntu | — | Upgrade dosfstools | May 31, 2016 | May 31, 2016 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 3, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub