CVE-2015-1572

CVSS v2.0 4.6 (Medium)
46% Progress
EPSS 0.04 % (11th)
0.04% Progress
Affected Products 3
Advisories 9

Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.

Weaknesses
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Related CVEs
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2015-02-24 15:59:05
(9 years ago)
Updated Date
2017-11-08 02:29:01
(6 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  E2fsprogs Project E2fsprogs 1.42.11 and prior versions cpe:2.3:a:e2fsprogs_project:e2fsprogs <= 1.42.11

Configuration #2

    CPE23 From Up To
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0

Configuration #3

    CPE23 From Up To
  Canonical Ubuntu Linux 10.04 cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts
  Canonical Ubuntu Linux 14.10 cpe:2.3:o:canonical:ubuntu_linux:14.10
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...