4.6
CVSSv2

CVE-2015-0247

Published: 17/02/2015 Updated: 09/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs prior to 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

e2fsprogs project e2fsprogs

debian debian linux 7.0

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

canonical ubuntu linux 14.10

canonical ubuntu linux 10.04

fedoraproject fedora 20

fedoraproject fedora 21

Vendor Advisories

Debian Bug report logs - #778948 e2fsprogs: CVE-2015-1572 buffer overflow Package: src:e2fsprogs; Maintainer for src:e2fsprogs is Theodore Y Ts'o <tytso@mitedu>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Sun, 22 Feb 2015 01:51:01 UTC Severity: serious Tags: patch, security Fixed in versions e2fsprog ...
e2fsprogs could be made to crash or run programs as an administrator if it processed a specially crafted filesystem image ...
A heap-based buffer overflow flaw was found in e2fsprogs A specially crafted Ext2/3/4 file system could cause an application using the ext2fs library (for example, fsck) to crash or, possibly, execute arbitrary code ...
A heap-based buffer overflow flaw was found in e2fsprogs A specially crafted Ext2/3/4 file system could cause an application using the ext2fs library (for example, fsck) to crash or, possibly, execute arbitrary code ...
A heap-based buffer overflow flaw was found in e2fsprogs A specially crafted Ext2/3/4 file system could cause an application using the ext2fs library (for example, fsck) to crash or, possibly, execute arbitrary code ...