First published: Fri Dec 07 2007(Updated: )
Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
E2fsprogs | <=1.40.2 | |
E2fsprogs | =1.18 | |
E2fsprogs | =1.12 | |
E2fsprogs | =1.40.1 | |
E2fsprogs | =1.08 | |
E2fsprogs | =1.14 | |
E2fsprogs | =1.04 | |
E2fsprogs | =1.37 | |
E2fsprogs | =1.07 | |
E2fsprogs | =1.40 | |
E2fsprogs | =1.28 | |
E2fsprogs | =1.21 | |
E2fsprogs | =1.13 | |
E2fsprogs | =1.15 | |
E2fsprogs | =1.27 | |
E2fsprogs | =1.29 | |
E2fsprogs | =1.25 | |
E2fsprogs | =1.32 | |
E2fsprogs | =1.35 | |
E2fsprogs | =1.22 | |
E2fsprogs | =1.34 | |
E2fsprogs | =1.05 | |
E2fsprogs | =1.38 | |
E2fsprogs | =1.19 | |
E2fsprogs | =1.02 | |
E2fsprogs | =1.20 | |
E2fsprogs | =1.17 | |
E2fsprogs | =1.26 | |
E2fsprogs | =1.33 | |
E2fsprogs | =1.39 | |
E2fsprogs | =1.23 | |
E2fsprogs | =1.24 | |
E2fsprogs | =1.03 | |
E2fsprogs | =1.06 | |
E2fsprogs | =1.30 | |
E2fsprogs | =1.16 | |
E2fsprogs | =1.09 | |
E2fsprogs | =1.36 | |
E2fsprogs | =1.11 | |
E2fsprogs | =1.10 | |
E2fsprogs | =1.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5497 is rated as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2007-5497, upgrade e2fsprogs to version 1.40.3 or later.
CVE-2007-5497 affects all versions of e2fsprogs prior to 1.40.3.
CVE-2007-5497 is an integer overflow vulnerability that can lead to buffer overflows.
Yes, CVE-2007-5497 can be exploited by remote attackers through crafted filesystem images.