Uninitialized Byte Leak in msdosfs(5) Dirent Structure

Uninitialized Byte Leak in msdosfs(5) Dirent Structure

CVE-2020-25579 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 11.4-RELEASE before p7 msdosfs(5) was failing to zero-fill a pair of padding fields in the dirent structure, resulting in a leak of three uninitialized bytes.

Learn more about our Web Application Penetration Testing UK.