GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Fri Mar 13, 2020 2:26 am Post subject: [ GLSA 202003-05 ] e2fsprogs |
|
|
Gentoo Linux Security Advisory
Title: e2fsprogs: Arbitrary code execution (GLSA 202003-05)
Severity: normal
Exploitable: local, remote
Date: 2020-03-13
Bug(s): #695522
ID: 202003-05
Synopsis
A vulnerability in e2fsprogs might allow an attacker to execute
arbitrary code.
Background
e2fsprogs is a set of utilities for maintaining the ext2, ext3 and ext4
file systems.
Affected Packages
Package: sys-fs/e2fsprogs
Vulnerable: < 1.45.4
Unaffected: >= 1.45.4
Architectures: All supported architectures
Description
It was discovered that e2fsprogs incorrectly handled certain ext4
partitions.
Impact
A remote attacker could entice a user to process a specially crafted
corrupted file system using e2fsck, possibly resulting in execution of
arbitrary code with the privileges of the process or a Denial of Service
condition.
Workaround
There is no known workaround at this time.
Resolution
All e2fsprogs users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=sys-fs/e2fsprogs-1.45.4"
|
References
CVE-2019-5094 |
|