CVE-2015-8872
MEDIUMCanonical Ubuntu Linux < 3.0.28 - Numeric Error
Title source: ruleDescription
The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clusters to the third to last entry on a FAT12 filesystem, which triggers an "off-by-two error."
References (9)
Scores
CVSS v3
6.2
EPSS
0.0008
EPSS Percentile
23.2%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-189
Status
draft
Affected Products (7)
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
opensuse/leap
opensuse/opensuse
dosfstools_project/dosfstools
< 3.0.28
Timeline
Published
Jun 03, 2016
Tracked Since
Feb 18, 2026