GLSA Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
Joined: 12 May 2004 Posts: 2663
|
Posted: Thu Jul 23, 2015 4:26 pm Post subject: [ GLSA 201507-22 ] e2fsprogs |
|
|
Gentoo Linux Security Advisory
Title: e2fsprogs: Arbitrary code execution (GLSA 201507-22)
Severity: normal
Exploitable: local
Date: July 23, 2015
Bug(s): #540536
ID: 201507-22
Synopsis
A heap-based buffer overflow in e2fsprogs could result in execution
of arbitrary code.
Background
e2fsprogs is a set of utilities for maintaining the ext2, ext3 and ext4
file systems.
Affected Packages
Package: sys-fs/e2fsprogs
Vulnerable: < 1.42.13
Unaffected: >= 1.42.13
Architectures: All supported architectures
Description
e2fsprogs has a heap-based buffer overflow in closefs.c in the libext2fs
library.
Impact
A local attacker could execute arbitrary code via a specially crafted
block group descriptor.
Workaround
There is no known workaround at this time.
Resolution
All e2fsprogs users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=sys-fs/e2fsprogs-1.42.13"
|
References
CVE-2015-1572 |
|