CVE-2019-5188Out-of-bounds Write in Project E2fsprogs

CWE-787Out-of-bounds Write14 documents11 sources
Severity
6.7MEDIUMNVD
CNA7.5
EPSS
0.1%
top 79.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 8
Latest updateDec 14

Description

A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages4 packages

Debiane2fsprogs_project/e2fsprogs< 1.45.5-1+3
NVDe2fsprogs_project/e2fsprogs1.43.31.45.4
CVEListV5e2fsprogs_project/e2fsprogs1.43.3 - 1.45.4
NVDopensuse/leap15.1

Also affects: Debian Linux 8.0, 9.0, Fedora 30, 31, Ubuntu Linux 12.04, 14.04, 16.04, 18.04, 19.04, 19.10

🔴Vulnerability Details

3
GHSA
GHSA-qv2m-8j7x-p5c8: A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 12022-05-24
OSV
CVE-2019-5188: A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 12020-01-08
CVEList
CVE-2019-5188: A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 12020-01-08

📋Vendor Advisories

5
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.12023-12-14
Ubuntu
e2fsprogs vulnerability2020-01-23
Microsoft
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack resulting in2020-01-14
Red Hat
e2fsprogs: Out-of-bounds write in e2fsck/rehash.c2020-01-07
Debian
CVE-2019-5188: e2fsprogs - A code execution vulnerability exists in the directory rehashing functionality o...2019

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Code execution vulnerability in E2fsprogs2020-01-09
Talos
Vulnerability Spotlight: Code execution vulnerability in E2fsprogs2020-01-09

💬Community

3
Bugzilla
CVE-2019-5188 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c [fedora-all]2020-01-17
Bugzilla
CVE-2019-5188 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c2020-01-11
Bugzilla
CVE-2019-5188 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c [fedora-all]2020-01-11
CVE-2019-5188 — Out-of-bounds Write | cvebase