On an msdosfs filesystem, the 'truncate' or 'ftruncate'...
Moderate severity
Unreviewed
Published
Oct 4, 2023
to the GitHub Advisory Database
•
Updated Dec 8, 2023
Description
Published by the National Vulnerability Database
Oct 4, 2023
Published to the GitHub Advisory Database
Oct 4, 2023
Last updated
Dec 8, 2023
On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes.
This may permit a user with write access to files on a msdosfs filesystem to read unintended data (e.g. from a previously deleted file).
References