MGASA-2015-0088
Dashboard / Vulnerabilities / MGASA-2015-0088
Summary: Updated e2fsprogs packages fix CVE-2015-1572
Details: Updated e2fsprogs packages fix security vulnerability: The libext2fs library, part of e2fsprogs and utilized by its utilities, is affected by a boundary check error on block group descriptor information, leading to a heap based buffer overflow. A specially crafted filesystem image can be used to trigger the vulnerability. This is due to an incomplete fix for CVE-2015-0247 (CVE-2015-1572).
References: https://advisories.mageia.org/MGASA-2015-0088.html, https://bugs.mageia.org/show_bug.cgi?id=15352, http://advisories.mageia.org/MGASA-2015-0061.html, https://www.debian.org/security/2015/dsa-3166
Affected packages
Package
Name: e2fsprogs
Purl: pkg:rpm/mageia/e2fsprogs?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
