Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published: 2018-04-13T15:00:00Z

Updated: 2024-09-17T04:15:15.844Z

Reserved: 2016-11-29T00:00:00

Link: CVE-2017-0358

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-04-13T15:29:00.397

Modified: 2019-10-03T00:03:26.223

Link: CVE-2017-0358

cve-icon Redhat

No data.