[e2fsprogs] [CVE-2007-5497] several integer overflows in memory allocating code

Bug #174174 reported by disabled.user
256
Affects Status Importance Assigned to Milestone
e2fsprogs (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: e2fsprogs

References:
[1] CVE-2007-5497 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5497)
[2] SUSE-SR:2007:025

Quoting [2]:
"e2fsprogs has been updated to fix several integer overflows in memory allocating code. Programs that use libext2fs are therefore vulnerable to memory corruptions that can lead to arbitrary code execution while loading a specially crafted image."

CVE References

Revision history for this message
disabled.user (disabled.user-deactivatedaccount) wrote :

Debian Security Advisory DSA-1422 (http://www.debian.org/security/2007/dsa-1422)

"Rafal Wojtczuk of McAfee AVERT Research discovered that e2fsprogs, ext2 file system utilities and libraries, contained multiple integer overflows in memory allocations, based on sizes taken directly from filesystem information. These could result in heap-based overflows potentially allowing the execution of arbitrary code.

For the stable distribution (etch), this problem has been fixed in version 1.39+1.40-WIP-2006.11.14+dfsg-2etch1."

Revision history for this message
Theodore Ts'o (tytso) wrote :

Note that pre-built .debs for Ubuntu Gutsy (for e2fsprogs 1.40.3, which fixes a number of additional bugs over 1.40.2) can be found at http://userweb.kernel.org/~tytso/e2-pre-release/ubuntu

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Fixed on Dapper - Gutsy: http://www.ubuntu.com/usn/usn-555-1

Request to sync with Debian for Hardy already made (#175544)

Changed in e2fsprogs:
status: New → Fix Released
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Hardy now has 1.40.3-1

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.