Medium severity6.2NVD Advisory· Published Jun 3, 2016· Updated May 6, 2026
CVE-2015-8872
CVE-2015-8872
Description
The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clusters to the third to last entry on a FAT12 filesystem, which triggers an "off-by-two error."
Affected products
12cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- osv-coords5 versionspkg:rpm/suse/dosfstools&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/dosfstools&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/dosfstools&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/dosfstools&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/dosfstools&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1
< 3.0.26-6.5+ 4 more
- (no CPE)range: < 3.0.26-6.5
- (no CPE)range: < 3.0.26-3.1
- (no CPE)range: < 3.0.26-6.5
- (no CPE)range: < 3.0.26-3.1
- (no CPE)range: < 3.0.26-6.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- github.com/dosfstools/dosfstools/releases/tag/v4.0nvdPatch
- blog.fuzzing-project.org/44-dosfstools-fsck.vfat-Several-invalid-memory-accesses.htmlnvdVendor Advisory
- github.com/dosfstools/dosfstools/issues/12nvdVendor Advisory
- lists.opensuse.org/opensuse-updates/2016-06/msg00001.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-09/msg00014.htmlnvd
- www.securityfocus.com/bid/90311nvd
- www.ubuntu.com/usn/USN-2986-1nvd
- github.com/dosfstools/dosfstools/commit/07908124838afcc99c577d1d3e84cef2dbd39cb7nvd
- lists.debian.org/debian-lts-announce/2020/05/msg00028.htmlnvd
News mentions
0No linked articles in our index yet.