{"id":"CVE-2016-4804","details":"The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function.","modified":"2026-07-08T12:27:21.787581Z","published":"2016-06-03T14:59:06.263Z","related":["SUSE-SU-2016:2145-1","SUSE-SU-2016:2146-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"],"extracted_events":[{"introduced":"12.04"},{"last_affected":"12.04"},{"introduced":"14.04"},{"last_affected":"14.04"},{"introduced":"15.10"},{"last_affected":"15.10"},{"introduced":"16.04"},{"last_affected":"16.04"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"},{"cpes":["cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"42.1"},{"last_affected":"42.1"}],"source":"CPE_STRING","vendor_product":"opensuse:leap"},{"cpes":["cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"13.2"},{"last_affected":"13.2"}],"source":"CPE_STRING","vendor_product":"opensuse:opensuse"}]},"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2016-06/msg00001.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2016-09/msg00014.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/90311"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2020/05/msg00028.html"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2986-1"},{"type":"FIX","url":"https://blog.fuzzing-project.org/44-dosfstools-fsck.vfat-Several-invalid-memory-accesses.html"},{"type":"FIX","url":"https://github.com/dosfstools/dosfstools/commit/e8eff147e9da1185f9afd5b25948153a3b97cf52"},{"type":"FIX","url":"https://github.com/dosfstools/dosfstools/issues/25"},{"type":"FIX","url":"https://github.com/dosfstools/dosfstools/issues/26"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dosfstools/dosfstools","events":[{"introduced":"0"},{"last_affected":"85022fe3d5b77b93eb20e4abc23c32577bf87f66"},{"fixed":"e8eff147e9da1185f9afd5b25948153a3b97cf52"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:dosfstools_project:dosfstools:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.0.28"}]}}],"versions":["v3.0.28","v3.0.27","v3.0.26","v3.0.25","v3.0.24","v3.0.23","v3.0.22","v3.0.21","v3.0.20","v3.0.19","v3.0.18","v3.0.17","v3.0.16","v3.0.15","v3.0.14","v3.0.13","v3.0.12","v3.0.11","v3.0.10","v3.0.9","v3.0.8","v3.0.7","v3.0.6","v3.0.5","v3.0.4","v3.0.3","v3.0.2","v3.0.1","v3.0.0","v2.11"],"database_specific":{"vanir_signatures_modified":"2026-07-08T12:27:21Z","vanir_signatures":[{"digest":{"line_hashes":["255238865409327844582568164948428438254","296336368702393128014096494827826443096","249431492176246829047427151907692272903","282019438315538498064837545060089201378"],"threshold":0.9},"id":"CVE-2016-4804-09e237fb","signature_type":"Line","signature_version":"v1","source":"https://github.com/dosfstools/dosfstools/commit/e8eff147e9da1185f9afd5b25948153a3b97cf52","target":{"file":"src/fsck.fat.h"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/dosfstools/dosfstools/commit/e8eff147e9da1185f9afd5b25948153a3b97cf52","target":{"file":"src/boot.c"},"deprecated":false,"digest":{"line_hashes":["123893220649092854101338150332848489365","246076588014694744016441002376821606785","234652834558211004894120601838777277930","37782068935701612668410896084110296969","62940619999127294059429895112190215076","184447703702203650960308840146322049230","58277623227777508570917265192641940546","9106026769713263517168966196591652612","314301353423495558072457380159332437364","309025116302605566367662688958809107069","6560462551031292577615086526307401300","73662561019436316449091922791231850662","303579489349651633726667624743072950613","212272853399085334098005315932532203058","24249371459950878624002050742472740","250262124380751608593672336401196944913","22759964055712584824017748468580141889","194504094987571186023832553265535138106","196753350449575500786119988144394279357","32012460471004387715938225234746519476"],"threshold":0.9},"id":"CVE-2016-4804-3c4fdeb9"},{"target":{"function":"dump_boot","file":"src/boot.c"},"deprecated":false,"digest":{"function_hash":"77701543821825306139960602256486180703","length":2283},"id":"CVE-2016-4804-967aa689","signature_type":"Function","signature_version":"v1","source":"https://github.com/dosfstools/dosfstools/commit/e8eff147e9da1185f9afd5b25948153a3b97cf52"},{"deprecated":false,"digest":{"function_hash":"157353839392065048035445465538445571550","length":4476},"id":"CVE-2016-4804-f2fc88f6","signature_type":"Function","signature_version":"v1","source":"https://github.com/dosfstools/dosfstools/commit/e8eff147e9da1185f9afd5b25948153a3b97cf52","target":{"file":"src/boot.c","function":"read_boot"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4804.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}