CVE-2007-5497
published 2007-12-07CVE-2007-5497: Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem…
PriorityP430medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
4.14%
89.7th percentile
Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | e2fsprogs | < e2fsprogs 1.40.3-1 (bookworm) | e2fsprogs 1.40.3-1 (bookworm) |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.40.3-1 | 1.40.3-1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.40.3-1 | 1.40.3-1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.40.3-1 | 1.40.3-1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.40.3-1 | 1.40.3-1 |
| ext2_filesystems_utilities | e2fsprogs | <= 1.40.2 | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
| ext2_filesystems_utilities | e2fsprogs | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
e2fsprogs vulnerability
vendor_ubuntu·2007-12-08
CVE-2007-5497 e2fsprogs vulnerability
Title: e2fsprogs vulnerability
Summary: e2fsprogs vulnerability
Rafal Wojtczuk discovered multiple integer overflows in e2fsprogs. If a
user or automated system were tricked into fscking a malicious ext2/ext3
filesystem, a remote attacker could execute arbitrary code with the user's
privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
e2fsprogs multiple integer overflows
vendor_redhat·2007-12-05·CVSS 5.8
CVE-2007-5497 [MEDIUM] CWE-190 e2fsprogs multiple integer overflows
e2fsprogs multiple integer overflows
Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image.
Debian
CVE-2007-5497: e2fsprogs - Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-as...
vendor_debian·2007·CVSS 5.8
CVE-2007-5497 [MEDIUM] CVE-2007-5497: e2fsprogs - Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-as...
Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image.
Scope: local
bookworm: resolved (fixed in 1.40.3-1)
bullseye: resolved (fixed in 1.40.3-1)
forky: resolved (fixed in 1.40.3-1)
sid: resolved (fixed in 1.40.3-1)
trixie: resolved (fixed in 1.40.3-1)
GHSA
GHSA-r9pv-wqv4-69wf: Multiple integer overflows in libext2fs in e2fsprogs before 1
ghsa_unreviewed·2022-05-01
CVE-2007-5497 [MEDIUM] GHSA-r9pv-wqv4-69wf: Multiple integer overflows in libext2fs in e2fsprogs before 1
Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image.
OSV
CVE-2007-5497: Multiple integer overflows in libext2fs in e2fsprogs before 1
osv·2007-12-07·CVSS 5.8
CVE-2007-5497 [MEDIUM] CVE-2007-5497: Multiple integer overflows in libext2fs in e2fsprogs before 1
Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-5497 e2fsprogs multiple integer overflows [F8]
bugzilla·2007-12-06·CVSS 5.8
CVE-2007-5497 [MEDIUM] CVE-2007-5497 e2fsprogs multiple integer overflows [F8]
CVE-2007-5497 e2fsprogs multiple integer overflows [F8]
F8 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
e2fsprogs-1.40.2-12.fc8, push to testing repo requested.
---
e2fsprogs-1.40.2-12.fc8 has been pushed to the Fedora 8 testing repository. If problems still persist, please make note of it in this bug report.
If you want to test the update, you can install it with
su -c 'yum --enablerepo=updates-testing update e2fsprogs'
---
e2fsprogs-1.40.2-12.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-5497 e2fsprogs multiple integer overflows [F6]
bugzilla·2007-12-06·CVSS 5.8
CVE-2007-5497 [MEDIUM] CVE-2007-5497 e2fsprogs multiple integer overflows [F6]
CVE-2007-5497 e2fsprogs multiple integer overflows [F6]
F6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
[22:08] do we still do security updates for FC6?
[22:08] nope!
[22:09] FC6 is officially past its EOL date
That EOL data was 1 day after this bug was filed, FWIW. Didn't get it done.
-Eric
Bugzilla
CVE-2007-5497 e2fsprogs multiple integer overflows [F7]
bugzilla·2007-12-06·CVSS 5.8
CVE-2007-5497 [MEDIUM] CVE-2007-5497 e2fsprogs multiple integer overflows [F7]
CVE-2007-5497 e2fsprogs multiple integer overflows [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
e2fsprogs-1.40.2-3.fc7, push to testing repo requested.
---
e2fsprogs-1.40.2-3.fc7 has been pushed to the Fedora 7 testing repository. If problems still persist, please make note of it in this bug report.
If you want to test the update, you can install it with
su -c 'yum --enablerepo=updates-testing update e2fsprogs'
---
e2fsprogs-1.40.2-3.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-5497 e2fsprogs multiple integer overflows [Fdevel]
bugzilla·2007-12-06·CVSS 5.8
CVE-2007-5497 [MEDIUM] CVE-2007-5497 e2fsprogs multiple integer overflows [Fdevel]
CVE-2007-5497 e2fsprogs multiple integer overflows [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
e2fsprogs-1.40.2-14.fc9
Bugzilla
CVE-2007-5497 e2fsprogs multiple integer overflows
bugzilla·2007-11-28·CVSS 5.8
CVE-2007-5497 [MEDIUM] CVE-2007-5497 e2fsprogs multiple integer overflows
CVE-2007-5497 e2fsprogs multiple integer overflows
Rafal Wojtczuk of McAfee AVERT Research discovered multiple integer overflows in
e2fsprogs. These flaws could result in the execution of arbitrary code if a
program using libext2fs (e2fsck, dumpe2fs, pygrub) is used to process a
malicious filesystem.
Under normal conditions this practice is not common. The most plausible attack
would be to leverage this flaw in a virtualized environment to gain access to dom0.
Acknowledgements:
Red Hat would like to thank Rafal Wojtczuk of McAfee Avert Research for responsibly disclosing these issues.
Discussion:
Created attachment 271731
Proposed upstream patch
---
This is public now:
https://bugs.launchpad.net/ubuntu/+source/e2fsprogs/+bug/174174
http://www.novell.com/linux/security/advisories/2
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083http://lists.vmware.com/pipermail/security-announce/2008/000007.htmlhttp://secunia.com/advisories/27889http://secunia.com/advisories/27965http://secunia.com/advisories/27987http://secunia.com/advisories/28000http://secunia.com/advisories/28030http://secunia.com/advisories/28042http://secunia.com/advisories/28360http://secunia.com/advisories/28541http://secunia.com/advisories/28648http://secunia.com/advisories/29224http://secunia.com/advisories/32774http://secunia.com/advisories/40551http://sourceforge.net/project/shownotes.php?release_id=560230&group_id=2406http://support.avaya.com/elmodocs2/security/ASA-2008-040.htmhttp://support.citrix.com/article/CTX118766http://wiki.rpath.com/Advisories:rPSA-2007-0262http://www.debian.org/security/2007/dsa-1422http://www.mandriva.com/security/advisories?name=MDKSA-2007:242http://www.novell.com/linux/security/advisories/2007_25_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0003.htmlhttp://www.securityfocus.com/archive/1/487999/100/0/threadedhttp://www.securityfocus.com/archive/1/489082/100/0/threadedhttp://www.securityfocus.com/bid/26772http://www.securitytracker.com/id?1019537http://www.ubuntu.com/usn/usn-555-1http://www.vmware.com/security/advisories/VMSA-2008-0004.htmlhttp://www.vupen.com/english/advisories/2007/4135http://www.vupen.com/english/advisories/2008/0761http://www.vupen.com/english/advisories/2010/1796https://exchange.xforce.ibmcloud.com/vulnerabilities/38903https://issues.rpath.com/browse/RPL-2011https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10399https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00618.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00629.htmlhttp://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083http://lists.vmware.com/pipermail/security-announce/2008/000007.htmlhttp://secunia.com/advisories/27889http://secunia.com/advisories/27965http://secunia.com/advisories/27987http://secunia.com/advisories/28000http://secunia.com/advisories/28030http://secunia.com/advisories/28042http://secunia.com/advisories/28360http://secunia.com/advisories/28541http://secunia.com/advisories/28648http://secunia.com/advisories/29224http://secunia.com/advisories/32774http://secunia.com/advisories/40551http://sourceforge.net/project/shownotes.php?release_id=560230&group_id=2406http://support.avaya.com/elmodocs2/security/ASA-2008-040.htmhttp://support.citrix.com/article/CTX118766http://wiki.rpath.com/Advisories:rPSA-2007-0262http://www.debian.org/security/2007/dsa-1422http://www.mandriva.com/security/advisories?name=MDKSA-2007:242http://www.novell.com/linux/security/advisories/2007_25_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0003.htmlhttp://www.securityfocus.com/archive/1/487999/100/0/threadedhttp://www.securityfocus.com/archive/1/489082/100/0/threadedhttp://www.securityfocus.com/bid/26772http://www.securitytracker.com/id?1019537http://www.ubuntu.com/usn/usn-555-1http://www.vmware.com/security/advisories/VMSA-2008-0004.htmlhttp://www.vupen.com/english/advisories/2007/4135http://www.vupen.com/english/advisories/2008/0761http://www.vupen.com/english/advisories/2010/1796https://exchange.xforce.ibmcloud.com/vulnerabilities/38903https://issues.rpath.com/browse/RPL-2011https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10399https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00618.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00629.html
2007-12-07
Published