CVE-2015-0247
published 2015-02-17CVE-2015-0247: Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block…
PriorityP426medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.90%
55.6th percentile
Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | e2fsprogs | < e2fsprogs 1.42.12-1 (bookworm) | e2fsprogs 1.42.12-1 (bookworm) |
| debian | e2fsprogs | < e2fsprogs 1.42.12-1.1 (bookworm) | e2fsprogs 1.42.12-1.1 (bookworm) |
| e2fsprogs_project | e2fsprogs | <= 1.42.11 | — |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.42.12-1 | 1.42.12-1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.42.12-1.1 | 1.42.12-1.1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.42.12-1 | 1.42.12-1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.42.12-1.1 | 1.42.12-1.1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.42.12-1 | 1.42.12-1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.42.12-1.1 | 1.42.12-1.1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.42.12-1 | 1.42.12-1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.42.12-1.1 | 1.42.12-1.1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.42.9-3ubuntu1.2 | 1.42.9-3ubuntu1.2 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
e2fsprogs vulnerabilities
vendor_ubuntu·2015-02-23·CVSS 4.6
CVE-2015-0247 [MEDIUM] e2fsprogs vulnerabilities
Title: e2fsprogs vulnerabilities
Summary: e2fsprogs could be made to crash or run programs as an administrator
if it processed a specially crafted filesystem image.
Jose Duart discovered that e2fsprogs incorrectly handled invalid block
group descriptor data. A local attacker could use this issue with a
crafted filesystem image to possibly execute arbitrary code.
(CVE-2015-0247, CVE-2015-1572)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
e2fsprogs: potential buffer overflow in closefs() (incomplete CVE-2015-0247 fix)
vendor_redhat·2015-02-11·CVSS 4.6
CVE-2015-1572 [MEDIUM] CWE-122 e2fsprogs: potential buffer overflow in closefs() (incomplete CVE-2015-0247 fix)
e2fsprogs: potential buffer overflow in closefs() (incomplete CVE-2015-0247 fix)
Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.
A heap-based buffer overflow flaw was found in e2fsprogs. A specially crafted Ext2/3/4 file system could cause an application using the ext2fs library (for example, fsck) to crash or, possibly, execute arbitrary code.
Statement: This issue affects e2fsprogs packages as shipped with Red Hat Enterprise Linux 6 and 7. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Is
Red Hat
e2fsprogs: ext2fs_open2() missing first_meta_bg boundary check leading to heap buffer overflow (oCERT-015-002)
vendor_redhat·2015-02-05·CVSS 4.6
CVE-2015-0247 [MEDIUM] CWE-122 e2fsprogs: ext2fs_open2() missing first_meta_bg boundary check leading to heap buffer overflow (oCERT-015-002)
e2fsprogs: ext2fs_open2() missing first_meta_bg boundary check leading to heap buffer overflow (oCERT-015-002)
Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
A heap-based buffer overflow flaw was found in e2fsprogs. A specially crafted Ext2/3/4 file system could cause an application using the ext2fs library (for example, fsck) to crash or, possibly, execute arbitrary code.
Package: e2fsprogs (Red Hat Enterprise Linux 5) - Not affected
Package: e4fsprogs (Red Hat Enterprise Linux 5) - Will not fix
Package: e2fsprogs (Red Hat Enterprise Linux 6) - Will not fix
Package: e2fsprogs (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-0247: e2fsprogs - Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs bef...
vendor_debian·2015·CVSS 4.6
CVE-2015-0247 [MEDIUM] CVE-2015-0247: e2fsprogs - Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs bef...
Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
Scope: local
bookworm: resolved (fixed in 1.42.12-1)
bullseye: resolved (fixed in 1.42.12-1)
forky: resolved (fixed in 1.42.12-1)
sid: resolved (fixed in 1.42.12-1)
trixie: resolved (fixed in 1.42.12-1)
Debian
CVE-2015-1572: e2fsprogs - Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs be...
vendor_debian·2015·CVSS 4.6
CVE-2015-1572 [MEDIUM] CVE-2015-1572: e2fsprogs - Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs be...
Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.
Scope: local
bookworm: resolved (fixed in 1.42.12-1.1)
bullseye: resolved (fixed in 1.42.12-1.1)
forky: resolved (fixed in 1.42.12-1.1)
sid: resolved (fixed in 1.42.12-1.1)
trixie: resolved (fixed in 1.42.12-1.1)
GHSA
GHSA-6f5v-c85c-6x7f: Heap-based buffer overflow in closefs
ghsa_unreviewed·2022-05-17·CVSS 4.6
CVE-2015-1572 [MEDIUM] CWE-119 GHSA-6f5v-c85c-6x7f: Heap-based buffer overflow in closefs
Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.
GHSA
GHSA-33r9-2w5v-33vg: Heap-based buffer overflow in openfs
ghsa_unreviewed·2022-05-14
CVE-2015-0247 [MEDIUM] CWE-119 GHSA-33r9-2w5v-33vg: Heap-based buffer overflow in openfs
Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
OSV
CVE-2015-1572: Heap-based buffer overflow in closefs
osv·2015-02-24·CVSS 4.6
CVE-2015-1572 [MEDIUM] CVE-2015-1572: Heap-based buffer overflow in closefs
Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.
OSV
e2fsprogs vulnerabilities
osv·2015-02-23·CVSS 4.6
CVE-2015-0247 [MEDIUM] e2fsprogs vulnerabilities
e2fsprogs vulnerabilities
Jose Duart discovered that e2fsprogs incorrectly handled invalid block
group descriptor data. A local attacker could use this issue with a
crafted filesystem image to possibly execute arbitrary code.
(CVE-2015-0247, CVE-2015-1572)
OSV
CVE-2015-0247: Heap-based buffer overflow in openfs
osv·2015-02-17·CVSS 4.6
CVE-2015-0247 [MEDIUM] CVE-2015-0247: Heap-based buffer overflow in openfs
Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1572 e2fsprogs: potential buffer overflow in closefs() (incomplete CVE-2015-0247 fix)
bugzilla·2015-02-18·CVSS 4.6
CVE-2015-1572 [MEDIUM] CVE-2015-1572 e2fsprogs: potential buffer overflow in closefs() (incomplete CVE-2015-0247 fix)
CVE-2015-1572 e2fsprogs: potential buffer overflow in closefs() (incomplete CVE-2015-0247 fix)
From the upstream commit [1]:
"""
The bug fix in f66e6ce4446: "libext2fs: avoid buffer overflow if s_first_meta_bg is too big" had a typo in the fix for ext2fs_closefs(). In practice most of the security exposure was from the openfs path, since this meant if there was a carefully crafted file system, buffer overrun would be triggered when the file system was opened. However, if corrupted file system didn't trip over some corruption check, and then the file system was modified via tune2fs or debugfs, such that the superblock was marked dirty and then written out via the closefs() path, it's possible that the buffer overrun could be triggered when the file system is closed.
"""
[1]: https://git.k
Bugzilla
CVE-2015-0247 e2fsprogs: ext2fs_open2() missing first_meta_bg boundary check leading to heap buffer overflow (oCERT-015-002) [fedora-all]
bugzilla·2015-02-05·CVSS 4.6
CVE-2015-0247 [MEDIUM] CVE-2015-0247 e2fsprogs: ext2fs_open2() missing first_meta_bg boundary check leading to heap buffer overflow (oCERT-015-002) [fedora-all]
CVE-2015-0247 e2fsprogs: ext2fs_open2() missing first_meta_bg boundary check leading to heap buffer overflow (oCERT-015-002) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messag
Bugzilla
CVE-2015-0247 e2fsprogs: ext2fs_open2() missing first_meta_bg boundary check leading to heap buffer overflow (oCERT-015-002)
bugzilla·2015-01-29·CVSS 4.6
CVE-2015-0247 [MEDIUM] CVE-2015-0247 e2fsprogs: ext2fs_open2() missing first_meta_bg boundary check leading to heap buffer overflow (oCERT-015-002)
CVE-2015-0247 e2fsprogs: ext2fs_open2() missing first_meta_bg boundary check leading to heap buffer overflow (oCERT-015-002)
A heap buffer overflow was found in e2fsprgos lib/ext2fs/openfs.c.
It allows a trivial arbitrary memory write under certain conditions.
Given that fsck is affected, and that an ext2/3/4 image can force a filesystem check on mount, this will allow code execution on systems that have automount enabled by just plugging a device.
Acknowledgements:
Red Hat would like to thank oCERT for reporting these issues. oCERT acknowledges Jose Duart of the Google Security Team as the original reporter.
Discussion:
(In reply to Vasyl Kaigorodov from comment #0)
> A heap buffer overflow was found in e2fsprgos lib/ext2fs/openfs.c.
The report actually mentions "a couple of heap o
http://advisories.mageia.org/MGASA-2015-0061.htmlhttp://git.kernel.org/cgit/fs/ext2/e2fsprogs.git/commit/?id=f66e6ce4http://lists.fedoraproject.org/pipermail/package-announce/2015-February/149434.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/150606.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/150805.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00019.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00010.htmlhttp://packetstormsecurity.com/files/130283/e2fsprogs-Input-Sanitization.htmlhttp://www.debian.org/security/2015/dsa-3166http://www.mandriva.com/security/advisories?name=MDVSA-2015:045http://www.mandriva.com/security/advisories?name=MDVSA-2015:067http://www.ocert.org/advisories/ocert-2015-002.htmlhttp://www.securityfocus.com/archive/1/534633/100/0/threadedhttp://www.securityfocus.com/bid/72520http://www.ubuntu.com/usn/USN-2507-1https://bugzilla.redhat.com/show_bug.cgi?id=1187032https://exchange.xforce.ibmcloud.com/vulnerabilities/100740https://security.gentoo.org/glsa/201701-06http://advisories.mageia.org/MGASA-2015-0061.htmlhttp://git.kernel.org/cgit/fs/ext2/e2fsprogs.git/commit/?id=f66e6ce4http://lists.fedoraproject.org/pipermail/package-announce/2015-February/149434.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/150606.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/150805.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00019.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00010.htmlhttp://packetstormsecurity.com/files/130283/e2fsprogs-Input-Sanitization.htmlhttp://www.debian.org/security/2015/dsa-3166http://www.mandriva.com/security/advisories?name=MDVSA-2015:045http://www.mandriva.com/security/advisories?name=MDVSA-2015:067http://www.ocert.org/advisories/ocert-2015-002.htmlhttp://www.securityfocus.com/archive/1/534633/100/0/threadedhttp://www.securityfocus.com/bid/72520http://www.ubuntu.com/usn/USN-2507-1https://bugzilla.redhat.com/show_bug.cgi?id=1187032https://exchange.xforce.ibmcloud.com/vulnerabilities/100740https://security.gentoo.org/glsa/201701-06
2015-02-17
Published