CVE-2015-1572

Publication date 16 February 2015

Last updated 24 July 2024


Ubuntu priority

Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.

Status

Package Ubuntu Release Status
e2fsprogs 14.10 utopic
Fixed 1.42.10-1.1ubuntu1.2
14.04 LTS trusty
Fixed 1.42.9-3ubuntu1.2
12.04 LTS precise
Fixed 1.42-1ubuntu2.2
10.04 LTS lucid
Fixed 1.41.11-1ubuntu2.3

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
e2fsprogs

References

Related Ubuntu Security Notices (USN)

    • USN-2507-1
    • e2fsprogs vulnerabilities
    • 23 February 2015

Other references