CVE-2015-1572
Description
Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.115
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| ext2/ext3/ext4 file system utilities (USN-2507-1) e2fsprogs_1.42-1ubuntu2.2_i386.deb | Linux |
| ext2/ext3/ext4 file system utilities (USN-2507-1) e2fsprogs_1.42-1ubuntu2.2_amd64.deb | Linux |
| ext2/ext3/ext4 file system utilities (USN-2507-1) e2fsprogs_1.42.9-3ubuntu1.2_i386.deb | Linux |
| ext2/ext3/ext4 file system utilities (USN-2507-1) e2fsprogs_1.42.9-3ubuntu1.2_amd64.deb | Linux |
| e2fsprogs security update(DSA-3166-1) e2fsprogs_1.42.5-1.1+deb7u1_i386.deb | Linux |
| e2fsprogs security update(DSA-3166-1) e2fsprogs_1.42.5-1.1+deb7u1_amd64.deb | Linux |
| E2fsprogs 1.42.5-1.1+deb7u1 for Debian GNU/Linux 7 (wheezy) e2fsprogs_1.42.5-1.1+deb7u1_i386.deb | Linux |
| SUSE-SU-2015:1341-1(SUSE Linux Enterprise Desktop 12 ) e2fsprogs-1.42.11-7.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1341-1(SUSE Linux Enterprise Desktop 12 ) e2fsprogs-debuginfo-1.42.11-7.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1341-1(SUSE Linux Enterprise Desktop 12 ) e2fsprogs-debuginfo-32bit-1.42.11-7.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1341-1(SUSE Linux Enterprise Desktop 12 ) e2fsprogs-debugsource-1.42.11-7.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1341-1(SUSE Linux Enterprise Desktop 12 ) libcom_err2-1.42.11-7.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1341-1(SUSE Linux Enterprise Desktop 12 ) libcom_err2-32bit-1.42.11-7.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1341-1(SUSE Linux Enterprise Desktop 12 ) libcom_err2-debuginfo-1.42.11-7.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1341-1(SUSE Linux Enterprise Desktop 12 ) libcom_err2-debuginfo-32bit-1.42.11-7.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1341-1(SUSE Linux Enterprise Desktop 12 ) libext2fs2-1.42.11-7.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1341-1(SUSE Linux Enterprise Desktop 12 ) libext2fs2-debuginfo-1.42.11-7.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1364-1(SUSE Linux Enterprise Desktop 11 SP3 ) e2fsprogs-1.41.9-2.10.11.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1364-1(SUSE Linux Enterprise Desktop 11 SP3 ) libblkid1-2.19.1-6.62.7.x86_64.rpm | Linux |
| SUSE-SU-2015:1364-1(SUSE Linux Enterprise Desktop 11 SP3 ) libblkid1-32bit-2.19.1-6.62.7.x86_64.rpm | Linux |
| SUSE-SU-2015:1364-1(SUSE Linux Enterprise Desktop 11 SP3 ) libcom_err2-1.41.9-2.10.11.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1364-1(SUSE Linux Enterprise Desktop 11 SP3 ) libcom_err2-32bit-1.41.9-2.10.11.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1364-1(SUSE Linux Enterprise Desktop 11 SP3 ) libext2fs2-1.41.9-2.10.11.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1364-1(SUSE Linux Enterprise Desktop 11 SP3 ) libuuid-devel-2.19.1-6.62.7.x86_64.rpm | Linux |
| SUSE-SU-2015:1364-1(SUSE Linux Enterprise Desktop 11 SP3 ) libuuid1-2.19.1-6.62.7.x86_64.rpm | Linux |
| SUSE-SU-2015:1364-1(SUSE Linux Enterprise Desktop 11 SP3 ) libuuid1-32bit-2.19.1-6.62.7.x86_64.rpm | Linux |
| SUSE-SU-2015:1364-1(SUSE Linux Enterprise Desktop 11 SP3 ) uuid-runtime-2.19.1-6.62.7.x86_64.rpm | Linux |
| E2fsprogs-libs update (ELSA-2024-12730) e2fsprogs-libs-1.45.4-3.0.7.el7.i686.rpm | Linux |
| E2fsprogs-devel update (ELSA-2024-12730) e2fsprogs-devel-1.45.4-3.0.7.el7.x86_64.rpm | Linux |
| E2fsprogs-devel update (ELSA-2024-12730) e2fsprogs-devel-1.45.4-3.0.7.el7.i686.rpm | Linux |
| Libss-devel update (ELSA-2024-12730) libss-devel-1.45.4-3.0.7.el7.x86_64.rpm | Linux |
| E2fsprogs update (ELSA-2024-12730) e2fsprogs-1.45.4-3.0.7.el7.i686.rpm | Linux |
| Libss-devel update (ELSA-2024-12730) libss-devel-1.45.4-3.0.7.el7.i686.rpm | Linux |
| E2fsprogs update (ELSA-2024-12730) e2fsprogs-1.45.4-3.0.7.el7.x86_64.rpm | Linux |
| Libss update (ELSA-2024-12730) libss-1.45.4-3.0.7.el7.i686.rpm | Linux |
| E2fsprogs-libs update (ELSA-2024-12730) e2fsprogs-libs-1.45.4-3.0.7.el7.x86_64.rpm | Linux |
| E2fsprogs-static update (ELSA-2024-12730) e2fsprogs-static-1.45.4-3.0.7.el7.i686.rpm | Linux |
| E2fsprogs-static update (ELSA-2024-12730) e2fsprogs-static-1.45.4-3.0.7.el7.x86_64.rpm | Linux |
| Libcom_err-devel update (ELSA-2024-12730) libcom_err-devel-1.45.4-3.0.7.el7.x86_64.rpm | Linux |
| Libcom_err-devel update (ELSA-2024-12730) libcom_err-devel-1.45.4-3.0.7.el7.i686.rpm | Linux |
| Libcom_err update (ELSA-2024-12730) libcom_err-1.45.4-3.0.7.el7.i686.rpm | Linux |
| Libcom_err update (ELSA-2024-12730) libcom_err-1.45.4-3.0.7.el7.x86_64.rpm | Linux |
| Libss update (ELSA-2024-12730) libss-1.45.4-3.0.7.el7.x86_64.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234