4.6
CVSSv2

CVE-2015-1572

Published: 24/02/2015 Updated: 08/11/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs prior to 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

e2fsprogs project e2fsprogs

debian debian linux 7.0

canonical ubuntu linux 10.04

canonical ubuntu linux 14.10

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

Vendor Advisories

Debian Bug report logs - #778948 e2fsprogs: CVE-2015-1572 buffer overflow Package: src:e2fsprogs; Maintainer for src:e2fsprogs is Theodore Y Ts'o <tytso@mitedu>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Sun, 22 Feb 2015 01:51:01 UTC Severity: serious Tags: patch, security Fixed in versions e2fsprog ...
e2fsprogs could be made to crash or run programs as an administrator if it processed a specially crafted filesystem image ...