CVE-2007-5497Integer Overflow or Wraparound in Filesystems Utilities E2fsprogs

Severity
5.8MEDIUMNVD
EPSS
3.0%
top 13.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 7
Latest updateMay 1

Description

Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-r9pv-wqv4-69wf: Multiple integer overflows in libext2fs in e2fsprogs before 12022-05-01
CVEList
CVE-2007-5497: Multiple integer overflows in libext2fs in e2fsprogs before 12007-12-07
OSV
CVE-2007-5497: Multiple integer overflows in libext2fs in e2fsprogs before 12007-12-07

📋Vendor Advisories

3
Ubuntu
e2fsprogs vulnerability2007-12-08
Red Hat
e2fsprogs multiple integer overflows2007-12-05
Debian
CVE-2007-5497: e2fsprogs - Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-as...2007

💬Community

5
Bugzilla
CVE-2007-5497 e2fsprogs multiple integer overflows [F8]2007-12-06
Bugzilla
CVE-2007-5497 e2fsprogs multiple integer overflows [F6]2007-12-06
Bugzilla
CVE-2007-5497 e2fsprogs multiple integer overflows [F7]2007-12-06
Bugzilla
CVE-2007-5497 e2fsprogs multiple integer overflows [Fdevel]2007-12-06
Bugzilla
CVE-2007-5497 e2fsprogs multiple integer overflows2007-11-28
CVE-2007-5497 — Integer Overflow or Wraparound | cvebase