Oval Definition:oval:org.cisecurity:def:240
Revision Date:2016-02-08Version:2
Title:DSA-3166-1 -- e2fsprogs -- security update
Description:Jose Duart of the Google Security Team discovered a buffer overflow in e2fsprogs, a set of utilities for the ext2, ext3, and ext4 file systems. This issue can possibly lead to arbitrary code execution if a malicious device is plugged in, the system is configured to automatically mount it, and the mounting process chooses to run fsck on the device's malicious filesystem.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2015-0247
CVE-2015-1572
DSA-3166-1
Platform(s):Debian GNU/kFreeBSD 7.0
Debian GNU/Linux 7.0
Product(s):e2fsprogs
Definition Synopsis
  • Debian 7 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND e2fsprogs is earlier than 0:1.42.5-1.1+deb7u1
  • BACK