security advisorybuffer overflowe2fsprogs
Lilith of Cisco Talos discovered a buffer overflow flaw in the quota code used by e2fsck from the ext2/ext3/ext4 file system utilities. Running e2fsck on a malformed file system can result in the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4535-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso September 27, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : e2fsprogs CVE ID : CVE-2019-5094 Debian Bug : 941139 Lilith of Cisco Talos discovered a buffer overflow flaw in the quota code used by e2fsck from the ext2/ext3/ext4 file system utilities. Running e2fsck on a malformed file system can result in the execution of arbitrary code. For the oldstable distribution (stretch), this problem has been fixed in version 1.43.4-2+deb9u1. For the stable distribution (buster), this problem has been fixed in version 1.44.5-1+deb10u2. We recommend that you upgrade your e2fsprogs packages. For the detailed security status of e2fsprogs please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/e2fsprogs Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Bulletin DSA-4536-1: e2fsprogs presents a critical memory corruption issue that could lead to potential exploitation in specific cases.. e2fsprogs buffer overflow, Debian security update, malformed filesystem issue, execution risk vulnerability. . LinuxSecurity.com Team
Sep 27, 2019
Debian