MGASA-2020-0436 - Updated f2fs-tools packages fix security vulnerability

Publication date: 23 Nov 2020
URL: https://advisories.mageia.org/MGASA-2020-0436.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-6070

An exploitable code execution vulnerability exists in the file system checking
functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a
logic flaw and out-of-bounds heap operations, resulting in code execution. An
attacker can provide a malicious file to trigger this vulnerability
(CVE-2020-6070).

References:
- https://bugs.mageia.org/show_bug.cgi?id=27413
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3SZ4HMQKNI35NBWJI6XMJBGWPEKZRR72/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6070

SRPMS:
- 7/core/f2fs-tools-1.14.0-1.mga7

Mageia 2020-0436: f2fs-tools security update

An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0

Summary

An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code execution. An attacker can provide a malicious file to trigger this vulnerability (CVE-2020-6070).

References

- https://bugs.mageia.org/show_bug.cgi?id=27413

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3SZ4HMQKNI35NBWJI6XMJBGWPEKZRR72/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6070

Resolution

MGASA-2020-0436 - Updated f2fs-tools packages fix security vulnerability

SRPMS

- 7/core/f2fs-tools-1.14.0-1.mga7

Severity
Publication date: 23 Nov 2020
URL: https://advisories.mageia.org/MGASA-2020-0436.html
Type: security
CVE: CVE-2020-6070

Related News