|
e2fsprogs libext2fs Integer Overflow Vulnerabilities
|
|
Secunia Advisory:
|
SA27889
|
|
|
Release Date:
|
2007-12-06
|
|
Last Update:
|
2007-12-19
|
|
Popularity:
|
6,945 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | e2fsprogs 1.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2007-5497
|
|
Description: Some vulnerabilities have been reported in the libext2fs library of e2fsprogs, which potentially can be exploited by malicious people to compromise an application using the library.
The vulnerabilities are caused due to integer overflows, which potentially can be exploited to execute arbitrary code by e.g. tricking a user into processing a specially crafted file system with an application using libext2fs.
Solution: Update to version 1.40.3.
http://sourceforge.net/project/showfi...package_id=2374&release_id=560230
Provided and/or discovered by: The vendor credits McAfee AVERT Research group.
Changelog: 2007-12-10: Updated "Solution" and "Original Advisory" sections.
2007-12-19: Updated "Provided and/or discovered by" section.
Original Advisory: SUSE:
http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00002.html
e2fsprogs:
http://sourceforge.net/project/shownotes.php?release_id=560230&group_id=2406
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|