PT-2007-7497 · Theodore Ts'O+1 · Uuid-Dev+13

Rafal Wojtczuk

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2007-5497

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions e2fsprogs versions prior to 1.40.3 e2fsprogs-devel versions prior to 1.40.3 e2fsprogs-libs versions prior to 1.40.3 libss2 versions (affected versions not specified) libuuid1-udeb versions (affected versions not specified) libcomerr2 versions (affected versions not specified) uuid-dev versions (affected versions not specified) comerr-dev versions (affected versions not specified) libuuid1 versions (affected versions not specified) e2fsck-static versions (affected versions not specified) e2fslibs versions (affected versions not specified) e2fslibs-dev versions (affected versions not specified) e2fsprogs-udeb versions (affected versions not specified)
Description The issue is related to multiple integer overflows in libext2fs in e2fsprogs, which can allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image. This can lead to a violation of confidentiality and integrity of protected information. The exploitation of the issue can be carried out remotely.
Recommendations For e2fsprogs versions prior to 1.40.3, update to version 1.40.3 or later. For e2fsprogs-devel versions prior to 1.40.3, update to version 1.40.3 or later. For e2fsprogs-libs versions prior to 1.40.3, update to version 1.40.3 or later. For libss2, libuuid1-udeb, libcomerr2, uuid-dev, comerr-dev, libuuid1, e2fsck-static, e2fslibs, e2fslibs-dev, and e2fsprogs-udeb, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02672
BDU:2015-02673
BDU:2015-02674
BDU:2015-02675
BDU:2015-02676
BDU:2015-02677
BDU:2015-02678
BDU:2015-02679
BDU:2015-02680
BDU:2015-02681
BDU:2015-02682
BDU:2015-07140
BDU:2015-07141
BDU:2015-07142
BDU:2015-07143
BDU:2015-07144
BDU:2015-07145
BDU:2015-07146
BDU:2015-09608
CVE-2007-5497
DSA-1422-1
DTSA-95-1
OPENSUSE-SU-2024:10731-1
RHSA-2008:0003
RHSA-2008_0003

Affected Products

Red Hat
Comerr-Dev
E2Fsck-Static
E2Fslibs
E2Fslibs-Dev
E2Fsprogs
E2Fsprogs-Devel
E2Fsprogs-Libs
E2Fsprogs-Udeb
Libcomerr2
Libssh2
Libuuid1
Libuuid1-Udeb
Uuid-Dev