Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-5188

Опубликовано: 08 янв. 2020
Источник: debian

Описание

A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
e2fsprogsfixed1.45.5-1package
e2fsprogsfixed1.44.5-1+deb10u3busterpackage

Примечания

  • Fixed by: https://git.kernel.org/pub/scm/fs/ext2/e2fsprogs.git/commit/?id=8dd73c149f418238f19791f9d666089ef9734dff

  • Further hardening: https://git.kernel.org/pub/scm/fs/ext2/e2fsprogs.git/commit/?id=71ba137571ba13755337e19c9a826dfc874562a36e1b24d3

  • https://talosintelligence.com/vulnerability_reports/TALOS-2019-0973

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

CVSS3: 7.5
redhat
около 6 лет назад

A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

CVSS3: 7.5
nvd
около 6 лет назад

A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

CVSS3: 6.7
msrc
около 5 лет назад

Описание отсутствует

suse-cvrf
около 6 лет назад

Security update for e2fsprogs