On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes.
This may permit a user with write access to files on a msdosfs filesystem to read unintended data (e.g. from a previously deleted file).
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: freebsd
Published: 2023-10-04T03:38:09.357Z
Updated: 2023-11-29T20:59:57.519Z
Reserved: 2023-10-03T21:14:20.733Z
Link: CVE-2023-5368
JSON object: View
NVD Information
Status : Modified
Published: 2023-10-04T04:15:14.143
Modified: 2023-11-29T21:15:07.940
Link: CVE-2023-5368
JSON object: View
Redhat Information
No data.
CWE