CVE-2019-5188
published 2020-01-08CVE-2019-5188: A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an…
PriorityP431medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
1.03%
59.7th percentile
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | e2fsprogs | < e2fsprogs 1.45.5-1 (bookworm) | e2fsprogs 1.45.5-1 (bookworm) |
| e2fsprogs_project | e2fsprogs | — | — |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.45.5-1 | 1.45.5-1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.45.5-1 | 1.45.5-1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.45.5-1 | 1.45.5-1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.45.5-1 | 1.45.5-1 |
| e2fsprogs_project | e2fsprogs | 1.43.3 – 1.45.4 | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_e2fsprogs_1.44.6-4_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv6.7MEDIUM
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_msrc6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
e2fsprogs vulnerability
vendor_ubuntu·2020-01-23
CVE-2019-5188 e2fsprogs vulnerability
Title: e2fsprogs vulnerability
Summary: e2fsprogs could be made to execute arbitrary code if it was running
in a crafted ext4 partition.
It was discovered that e2fsprogs incorrectly handled certain ext4 partitions.
An attacker could possibly use this issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack resulting in
vendor_msrc·2020-01-14·CVSS 6.7
CVE-2019-5188 [HIGH] CWE-787 A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack resulting in
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for m
Red Hat
e2fsprogs: Out-of-bounds write in e2fsck/rehash.c
vendor_redhat·2020-01-07·CVSS 7.5
CVE-2019-5188 [HIGH] CWE-787 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c
e2fsprogs: Out-of-bounds write in e2fsck/rehash.c
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
Package: e2fsprogs (Red Hat Enterprise Linux 5) - Out of support scope
Package: e2fsprogs (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2019-5188: e2fsprogs - A code execution vulnerability exists in the directory rehashing functionality o...
vendor_debian·2019·CVSS 7.5
CVE-2019-5188 [HIGH] CVE-2019-5188: e2fsprogs - A code execution vulnerability exists in the directory rehashing functionality o...
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 1.45.5-1)
bullseye: resolved (fixed in 1.45.5-1)
forky: resolved (fixed in 1.45.5-1)
sid: resolved (fixed in 1.45.5-1)
trixie: resolved (fixed in 1.45.5-1)
GHSA
GHSA-qv2m-8j7x-p5c8: A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1
ghsa_unreviewed·2022-05-24
CVE-2019-5188 [MEDIUM] CWE-787 GHSA-qv2m-8j7x-p5c8: A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
OSV
CVE-2019-5188: A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1
osv·2020-01-08·CVSS 6.7
CVE-2019-5188 [MEDIUM] CVE-2019-5188: A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Code execution vulnerability in E2fsprogs
blogs_talos·2020-01-09·CVSS 7.5
[HIGH] Vulnerability Spotlight: Code execution vulnerability in E2fsprogs
Lilith [^_^] of Cisco Talos discovered this vulnerability.
E2fsprogs contains an exploitable code execution vulnerability in its directory rehashing functionality. This set of programs is often considered essential software for many Linux and Unix
machines and ships by default on most Linux systems. An attacker could exploit this vulnerability by causing an out-of-bounds write on the stack, which would then allow them to execute code on the victim machine.
In accordance with our coordinated disclosure policy, Cisco Talos worked with E2fsprogs to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability details
E2fsprogs e2fsck rehash.c mutate_name() code execution vulnerability (TALOS-2019-0973/CVE-2019-5188)
A code execution vuln
Talos
Vulnerability Spotlight: Code execution vulnerability in E2fsprogs
blogs_talos·2020-01-09·CVSS 7.5
[HIGH] Vulnerability Spotlight: Code execution vulnerability in E2fsprogs
## Vulnerability Spotlight: Code execution vulnerability in E2fsprogs
Lilith [^_^] of Cisco Talos discovered this vulnerability.
E2fsprogs contains an exploitable code execution vulnerability in its directory rehashing functionality. This set of programs is often considered essential software for many Linux and Unix
machines and ships by default on most Linux systems. An attacker could exploit this vulnerability by causing an out-of-bounds write on the stack, which would then allow them to execute code on the victim machine.
In accordance with our coordinated disclosure policy, Cisco Talos worked with E2fsprogs to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details
E2fsprogs e2fsck rehash.c mutate_name() code executio
Bugzilla
CVE-2019-5188 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c [fedora-all]
bugzilla·2020-01-17·CVSS 7.5
CVE-2019-5188 [HIGH] CVE-2019-5188 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c [fedora-all]
CVE-2019-5188 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c [fedora-all]
+++ This bug was initially created as a clone of Bug #1790049 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg co
Bugzilla
CVE-2019-5188 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c
bugzilla·2020-01-11·CVSS 7.5
CVE-2019-5188 [HIGH] CVE-2019-5188 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c
CVE-2019-5188 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
References:
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0973
Upstream patches:
https://github.com/tytso/e2fsprogs/commit/8dd73c149f418238f19791f9d666089ef9734dff
https://github.com/tytso/e2fsprogs/commit/71ba13755337e19c9a826dfc874562a36e1b24d3
Discussion:
Created e2fsprogs tracking bugs for this issue:
Affects: fedora-all [bug 1790049]
---
There's an issue with fsck application contained on e2fsck package. The fsck ap
Bugzilla
CVE-2019-5188 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c [fedora-all]
bugzilla·2020-01-11·CVSS 7.5
CVE-2019-5188 [HIGH] CVE-2019-5188 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c [fedora-all]
CVE-2019-5188 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00004.htmlhttps://lists.debian.org/debian-lts-announce/2020/03/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DOBCYQKCTTWXBLMUPJ5TX3FY7JNCOKY/https://security.netapp.com/advisory/ntap-20220506-0001/https://talosintelligence.com/vulnerability_reports/TALOS-2019-0973https://usn.ubuntu.com/4249-1/http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00004.htmlhttps://lists.debian.org/debian-lts-announce/2020/03/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DOBCYQKCTTWXBLMUPJ5TX3FY7JNCOKY/https://security.netapp.com/advisory/ntap-20220506-0001/https://talosintelligence.com/vulnerability_reports/TALOS-2019-0973https://usn.ubuntu.com/4249-1/
2020-01-08
Published