Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

SUSE 15: 2018:1987-1 Moderate: e2fsprogs Heap Overflow Fix

suse
Calendar Grey July 19, 2018
Scroller Suse
A recent update addresses two vulnerabilities in e2fsprogs, implementing solutions for heap and buffer overflow concerns, thereby improving security on SUSE systems.
An update that solves two vulnerabilities and has three fixes is now available

Summary

This update for e2fsprogs fixes the following issues: Security issues fixed: - CVE-2015-0247: Fixed couple of heap overflows in e2fsprogs (fsck, dumpe2fs, e2image...) (bsc#915402). - CVE-2015-1572: Fixed potential buffer overflow in closefs() (bsc#918346). Bug fixes: - bsc#1038194: generic/405 test fails with /dev/mapper/thin-vol is inconsistent on ext4 file system. - bsc#1009532: resize2fs hangs when trying to resize a large ext4 file system. - bsc#960273: xfsprogs does not call %{?regenerate_initrd_post}. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15:

References

#1009532 #1038194 #915402 #918346 #960273

Cross- CVE-2015-0247 CVE-2015-1572

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2015-0247.html

https://www.suse.com/security/cve/CVE-2015-1572.html

https://bugzilla.suse.com/1009532

https://bugzilla.suse.com/1038194

https://bugzilla.suse.com/915402

https://bugzilla.suse.com/918346

https://bugzilla.suse.com/960273

Announcement ID: SUSE-SU-2018:1987-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.