SUSE SLED15 / SLES15 Security Update : ntfs-3g_ntfsprogs (SUSE-SU-2021:2971-1)

high Nessus Plugin ID 153122

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLES15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2021:2971-1 advisory.

Update to version 2021.8.22 (bsc#1189720):

* Fixed compile error when building with libfuse < 2.8.0
* Fixed obsolete macros in configure.ac
* Signalled support of UTIME_OMIT to external libfuse2
* Fixed an improper macro usage in ntfscp.c
* Updated the repository change in the README
* Fixed vulnerability threats caused by maliciously tampered NTFS partitions
* Security fixes: CVE-2021-33285, CVE-2021-33286, CVE-2021-33287, CVE-2021-33289, CVE-2021-35266, CVE-2021-35267, CVE-2021-35268, CVE-2021-35269, CVE-2021-39251, CVE-2021-39252, CVE-2021-39253, CVE_2021-39254, CVE-2021-39255, CVE-2021-39256, CVE-2021-39257, CVE-2021-39258, CVE-2021-39259, CVE-2021-39260, CVE-2021-39261, CVE-2021-39262, CVE-2021-39263.

- Library soversion is now 89

* Changes in version 2017.3.23
* Delegated processing of special reparse points to external plugins
* Allowed kernel cacheing by lowntfs-3g when not using Posix ACLs
* Enabled fallback to read-only mount when the volume is hibernated
* Made a full check for whether an extended attribute is allowed
* Moved secaudit and usermap to ntfsprogs (now ntfssecaudit and ntfsusermap)
* Enabled encoding broken UTF-16 into broken UTF-8
* Autoconfigured selecting <sys/sysmacros.h> vs <sys/mkdev>
* Allowed using the full library API on systems without extended attributes support
* Fixed DISABLE_PLUGINS as the condition for not using plugins
* Corrected validation of multi sector transfer protected records
* Denied creating/removing files from $Extend
* Returned the size of locale encoded target as the size of symlinks

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected libntfs-3g-devel, libntfs-3g87, ntfs-3g and / or ntfsprogs packages.

See Also

https://bugzilla.suse.com/1189720

https://www.suse.com/security/cve/CVE-2019-9755

https://www.suse.com/security/cve/CVE-2021-33285

https://www.suse.com/security/cve/CVE-2021-33286

https://www.suse.com/security/cve/CVE-2021-33287

https://www.suse.com/security/cve/CVE-2021-33289

https://www.suse.com/security/cve/CVE-2021-35266

https://www.suse.com/security/cve/CVE-2021-35267

https://www.suse.com/security/cve/CVE-2021-35268

https://www.suse.com/security/cve/CVE-2021-35269

https://www.suse.com/security/cve/CVE-2021-39251

https://www.suse.com/security/cve/CVE-2021-39252

https://www.suse.com/security/cve/CVE-2021-39253

https://www.suse.com/security/cve/CVE-2021-39255

https://www.suse.com/security/cve/CVE-2021-39256

https://www.suse.com/security/cve/CVE-2021-39257

https://www.suse.com/security/cve/CVE-2021-39258

https://www.suse.com/security/cve/CVE-2021-39259

https://www.suse.com/security/cve/CVE-2021-39260

https://www.suse.com/security/cve/CVE-2021-39261

https://www.suse.com/security/cve/CVE-2021-39262

https://www.suse.com/security/cve/CVE-2021-39263

http://www.nessus.org/u?04b5fc79

Plugin Details

Severity: High

ID: 153122

File Name: suse_SU-2021-2971-1.nasl

Version: 1.8

Type: Local

Agent: unix

Published: 9/8/2021

Updated: 6/26/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.0

CVSS v2

Risk Factor: Medium

Base Score: 6.9

Temporal Score: 6

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2021-39263

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:libntfs-3g87, p-cpe:/a:novell:suse_linux:ntfsprogs, p-cpe:/a:novell:suse_linux:ntfs-3g, p-cpe:/a:novell:suse_linux:libntfs-3g-devel, cpe:/o:novell:suse_linux:15

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/7/2021

Vulnerability Publication Date: 3/29/2019

Reference Information

CVE: CVE-2019-9755, CVE-2021-33285, CVE-2021-33286, CVE-2021-33287, CVE-2021-33289, CVE-2021-35266, CVE-2021-35267, CVE-2021-35268, CVE-2021-35269, CVE-2021-39251, CVE-2021-39252, CVE-2021-39253, CVE-2021-39255, CVE-2021-39256, CVE-2021-39257, CVE-2021-39258, CVE-2021-39259, CVE-2021-39260, CVE-2021-39261, CVE-2021-39262, CVE-2021-39263

SuSE: SUSE-SU-2021:2971-1