-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4413-1 security@xxxxxxxxxx https://www.debian.org/security/ Salvatore Bonaccorso March 21, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ntfs-3g CVE ID : CVE-2019-9755 A heap-based buffer overflow was discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of this flaw for local root privilege escalation. For the stable distribution (stretch), this problem has been fixed in version 1:2016.2.22AR.1+dfsg-1+deb9u1. We recommend that you upgrade your ntfs-3g packages. For the detailed security status of ntfs-3g please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ntfs-3g Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@xxxxxxxxxxxxxxxx -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlyT9CpfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0RsURAAg50+LqSrMKGcKRhKXsJvFKFXdyCzpe8I1mAAOh97deIHM3OYADBoIbWS h9B+uN/2Ue3INrB9KDLQHjDxtrddLHn5tZDGIIISl/5QRGgq5AbAXmtSFbm1EUzD lYeM9Qdh6NIlfr9GmnTe/XoJGatHzQmHMJnTQfdD1cnIXHUO0vQ0PNRTuhCrURH8 9XcWf27qBpViORDxl9NjIRF/QTg/lwQl+lv+VYtfLXjgvbsbalEi9JDkXsL07Noc kP5x2nxJzkX72AHsap/i00uXKYfJJ9MhXa+dIz9PQx+0QJjxs2bbPrAtrVPhKiHi uwxDhhzFR0n41pDGRPi0Xxxc5c/98bImY4tBatZacSabAuSd0bwI2Wu1Wsy8sYGB aIEkx01KcLOG8KdGlTmqsZoeZTJpnNKLuRPuBhZXIuEBGlHl5Z7wXF8GAeHqoLIt KppJNetczJESqWDBPW/VGRSTW8U3KIeM4ci+InZN9jKmlqVQipAco/6JNH6B4lb9 EnFJHDBnEYCdzbxLrEtoUnKXYPgHMOAtip6QBsEs/KA1B0MdsOW8yoDXUmyPfIT4 fAVyTdu8Z/S8WCfnLjJ/8lqC48fpcb/OSwKp42bUgHar/KIpgZ74qDtDqctRel8b x7Bo1xnJDbLsFqVwIQUSPBZ18mg+cPggGBm80T/TrlYyTVtqDco= =jmPt -----END PGP SIGNATURE-----