CVE-2019-5094Out-of-bounds Write in Project E2fsprogs

CWE-787Out-of-bounds Write13 documents10 sources
Severity
6.7MEDIUMNVD
CNA7.5
EPSS
0.3%
top 43.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 24
Latest updateDec 14

Description

An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages3 packages

Debiane2fsprogs_project/e2fsprogs< 1.45.4-1+3
NVDe2fsprogs_project/e2fsprogs1.43.31.45.3
CVEListV5e2fsprogs_project/e2fsprogsE2fsprogs 1.43.3 - 1.45.3

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 30, 31, Ubuntu Linux 12.04, 14.04, 16.04, 18.04, 19.04

🔴Vulnerability Details

3
GHSA
GHSA-3498-94v2-7qqw: An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 12022-05-24
CVEList
CVE-2019-5094: An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 12019-09-24
OSV
CVE-2019-5094: An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 12019-09-24

📋Vendor Advisories

6
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.12023-12-14
Ubuntu
e2fsprogs vulnerability2019-09-30
Ubuntu
e2fsprogs vulnerability2019-09-30
Microsoft
An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap resulting in cod2019-09-10
Red Hat
e2fsprogs: Crafted ext4 partition leads to out-of-bounds write2019-08-27

💬Community

3
Bugzilla
CVE-2019-5094 e2fsprogs: crafted ext4 partition leads to out-of-bounds write [fedora-all]2020-01-17
Bugzilla
CVE-2019-5094 e2fsprogs: Crafted ext4 partition leads to out-of-bounds write2019-11-04
Bugzilla
CVE-2019-5094 e2fsprogs: crafted ext4 partition leads to out-of-bounds write [fedora-all]2019-11-04
CVE-2019-5094 — Out-of-bounds Write | cvebase