Lucene search

K
ubuntuUbuntuUSN-555-1
HistoryDec 08, 2007 - 12:00 a.m.

e2fsprogs vulnerability

2007-12-0800:00:00
ubuntu.com
35

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

7.2

Confidence

Low

EPSS

0.142

Percentile

95.7%

Releases

  • Ubuntu 7.10
  • Ubuntu 7.04
  • Ubuntu 6.10
  • Ubuntu 6.06

Packages

  • e2fsprogs -

Details

Rafal Wojtczuk discovered multiple integer overflows in e2fsprogs. If a
user or automated system were tricked into fscking a malicious ext2/ext3
filesystem, a remote attacker could execute arbitrary code with the user’s
privileges.

OSVersionArchitecturePackageVersionFilename
Ubuntu7.10noarche2fslibs< 1.40.2-1ubuntu1.1UNKNOWN
Ubuntu7.10noarchcomerr-dev< 2.1-1.40.2-1ubuntu1.1UNKNOWN
Ubuntu7.10noarche2fsck-static< 1.40.2-1ubuntu1.1UNKNOWN
Ubuntu7.10noarche2fslibs-dev< 1.40.2-1ubuntu1.1UNKNOWN
Ubuntu7.10noarche2fsprogs< 1.40.2-1ubuntu1.1UNKNOWN
Ubuntu7.10noarche2fsprogs-udeb< 1.40.2-1ubuntu1.1UNKNOWN
Ubuntu7.10noarchlibblkid-dev< 1.40.2-1ubuntu1.1UNKNOWN
Ubuntu7.10noarchlibblkid1< 1.40.2-1ubuntu1.1UNKNOWN
Ubuntu7.10noarchlibblkid1-udeb< 1.40.2-1ubuntu1.1UNKNOWN
Ubuntu7.10noarchlibcomerr2< 1.40.2-1ubuntu1.1UNKNOWN
Rows per page:
1-10 of 601

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

7.2

Confidence

Low

EPSS

0.142

Percentile

95.7%