SB2019092436 - Out-of-bounds write in e2fsprogs (Alpine package)
Published: September 24, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2019-5094)
The vulnerability allows a local user to escalate privileges on the vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in the quota file functionality. A local user can send a specially crafted xt4 partition, trigger out-of-bounds write on the heap and execute arbitrary code on the target system.
Note: An attacker can corrupt a partition to trigger this vulnerability.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=961349519affeaa193ce9d638736f4482ff4576a
- https://git.alpinelinux.org/aports/commit/?id=00430c951fbd0bdf2423cd019cb974e2eb19361d
- https://git.alpinelinux.org/aports/commit/?id=d8efadc5c1f1ea65c6ae440cc76b28fd844055b2
- https://git.alpinelinux.org/aports/commit/?id=3ae476f3715e2011fce8fb62ecb98307aa497b10
- https://git.alpinelinux.org/aports/commit/?id=3e1d286c529c3cace0231414810b22b8b20198fa
- https://git.alpinelinux.org/aports/commit/?id=b07e4ca0bd5a1542b96c14bfb7c9aed7fd0eaa70
- https://git.alpinelinux.org/aports/commit/?id=bac324e9e42da71fd74dd386daf7f84aae6907dc
- https://git.alpinelinux.org/aports/commit/?id=0044289f304efdf4000c80392b388bad6dd07bb9