Joined: 12 May 2004
|Posted: Thu Jul 23, 2015 4:26 pm Post subject: [ GLSA 201507-22 ] e2fsprogs
|Gentoo Linux Security Advisory
Title: e2fsprogs: Arbitrary code execution (GLSA 201507-22)
Date: July 23, 2015
A heap-based buffer overflow in e2fsprogs could result in execution
of arbitrary code.
e2fsprogs is a set of utilities for maintaining the ext2, ext3 and ext4
Vulnerable: < 1.42.13
Unaffected: >= 1.42.13
Architectures: All supported architectures
e2fsprogs has a heap-based buffer overflow in closefs.c in the libext2fs
A local attacker could execute arbitrary code via a specially crafted
block group descriptor.
There is no known workaround at this time.
All e2fsprogs users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose ">=sys-fs/e2fsprogs-1.42.13"