First published: Tue Sep 24 2019(Updated: )
An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
Credit: talos-cna@cisco.com talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/e2fsprogs | <=1.44.5-1<=1.43.4-2<=1.44.5-1+deb10u1 | 1.45.4-1 1.44.5-1+deb10u2 1.43.4-2+deb9u1 |
debian/e2fsprogs | 1.46.2-2 1.47.0-2 1.47.1-1 | |
IBM InfoSphere Guardium z/OS | <=10.5 | |
IBM InfoSphere Guardium z/OS | <=10.6 | |
IBM InfoSphere Guardium z/OS | <=11.0 | |
IBM InfoSphere Guardium z/OS | <=11.1 | |
IBM InfoSphere Guardium z/OS | <=11.2 | |
IBM InfoSphere Guardium z/OS | <=11.3 | |
e2fsprogs | >=1.43.3<=1.45.3 | |
Debian | =8.0 | |
Debian | =9.0 | |
Debian | =10.0 | |
Fedora | =30 | |
Fedora | =31 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 | |
NetApp SolidFire & HCI Management Node | ||
NetApp SolidFire & HCI Storage Node |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.