{ "id": "CVE-2007-5497", "sourceIdentifier": "secalert@redhat.com", "published": "2007-12-07T11:46:00.000", "lastModified": "2024-11-21T00:38:02.387", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image." }, { "lang": "es", "value": "M\u00faltiples desbordamientos enteros en libext2fs en e2fsprogs versiones anteriores a 1.40.3, permiten a los atacantes remotos asistidos por el usuario ejecutar c\u00f3digo arbitrario por medio de una imagen del sistema de archivos especialmente dise\u00f1ada." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N", "baseScore": 5.8, "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 4.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-189" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:*:*:*:*:*:*:*:*", "versionEndIncluding": "1.40.2", "matchCriteriaId": "5AC81AB4-8B6F-4465-B0F9-BC7B1F72D6AC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.02:*:*:*:*:*:*:*", "matchCriteriaId": "BEE1E909-EA45-4E69-B743-82436045EC12" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.03:*:*:*:*:*:*:*", "matchCriteriaId": "F2B7983A-68C2-4626-8DE5-E8FA15B11CE2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.04:*:*:*:*:*:*:*", "matchCriteriaId": "86B9567E-A1F0-45AD-9572-DDC1B809FA02" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.05:*:*:*:*:*:*:*", "matchCriteriaId": "CAC3FE84-4183-4727-AFE0-9A48223E50DD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.06:*:*:*:*:*:*:*", "matchCriteriaId": "7AB0B87D-6288-4D16-BFFA-4420D137F0B5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.07:*:*:*:*:*:*:*", "matchCriteriaId": "6199DAD0-FCEB-4917-B0D1-BB823A3EE434" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.08:*:*:*:*:*:*:*", "matchCriteriaId": "02A625EB-0C5E-4654-9A21-2F8A4ABD2C70" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.09:*:*:*:*:*:*:*", "matchCriteriaId": "8C2FD6C1-8CE1-4C22-9952-5D400A8A6283" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.10:*:*:*:*:*:*:*", "matchCriteriaId": "D99BC504-67A4-4494-BFEB-2D49944C045A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.11:*:*:*:*:*:*:*", "matchCriteriaId": "78FFADA7-DD53-47CB-8AC5-DC46CDFEFE53" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.12:*:*:*:*:*:*:*", "matchCriteriaId": "6D6366A0-ED37-4850-95CB-BB9F9793549C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.13:*:*:*:*:*:*:*", "matchCriteriaId": "BE810EB3-685F-419C-B2E0-EBCB2E29D44E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.14:*:*:*:*:*:*:*", "matchCriteriaId": "8CA532D0-6B23-41B6-8ECD-4F6F8046EF62" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.15:*:*:*:*:*:*:*", "matchCriteriaId": "EB357247-9885-49AD-B7A4-AF4523D3AE96" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.16:*:*:*:*:*:*:*", "matchCriteriaId": "28D7F610-5EAD-46A2-BD42-FE4CF22650EC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.17:*:*:*:*:*:*:*", "matchCriteriaId": "83D1C237-0AE4-4E75-B10A-464DE4BA32DB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.18:*:*:*:*:*:*:*", "matchCriteriaId": "6FDAEECA-5C63-4D6F-AA41-934235D15465" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.19:*:*:*:*:*:*:*", "matchCriteriaId": "9CB8E29C-8038-41EF-82FB-27E249F0D946" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.20:*:*:*:*:*:*:*", "matchCriteriaId": "FB85C46E-AE17-4EC9-811F-872F9B018679" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.21:*:*:*:*:*:*:*", "matchCriteriaId": "5C46F88A-DF22-45D3-8CE8-A0C3EDE7C4A1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.22:*:*:*:*:*:*:*", "matchCriteriaId": "73A41A5C-5D90-4A13-ADBB-971B0872667C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.23:*:*:*:*:*:*:*", "matchCriteriaId": "0EEC84D7-456D-436F-B807-35434FC69A9A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.24:*:*:*:*:*:*:*", "matchCriteriaId": "0D615C9B-04B9-480A-8C19-681B720F09B5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.25:*:*:*:*:*:*:*", "matchCriteriaId": "58897ED4-3494-41C6-9EB3-88074D211023" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.26:*:*:*:*:*:*:*", "matchCriteriaId": "0F75FC1B-E440-4975-8FA4-088B9DA4376D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.27:*:*:*:*:*:*:*", "matchCriteriaId": "85E46684-0BB0-49D1-A028-440BD815B0A1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.28:*:*:*:*:*:*:*", "matchCriteriaId": "12F16B8E-49C0-4536-97A8-F284CF9BB61D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.29:*:*:*:*:*:*:*", "matchCriteriaId": "37893C89-282F-4376-917E-5DD31F2D832D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.30:*:*:*:*:*:*:*", "matchCriteriaId": "C8BD30BE-2E5C-4835-8DEF-FC59EF8A83C5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.31:*:*:*:*:*:*:*", "matchCriteriaId": "C36FCB50-2EAD-4ED7-AD5D-5FD197B8965B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.32:*:*:*:*:*:*:*", "matchCriteriaId": "0F30FAD6-F7AB-4734-BC13-F4DBF7983260" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.33:*:*:*:*:*:*:*", "matchCriteriaId": "0BAB51F0-A94E-4126-B50E-0F99D743D7AE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.34:*:*:*:*:*:*:*", "matchCriteriaId": "510DB0AF-A11E-4C2A-BD94-7D788EC156A7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.35:*:*:*:*:*:*:*", "matchCriteriaId": "2CDCB34E-D2A2-4AC8-828A-CAB77B68F2FE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.36:*:*:*:*:*:*:*", "matchCriteriaId": "A33EEDE8-9348-425C-AD88-AE10426B3DBA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.37:*:*:*:*:*:*:*", "matchCriteriaId": "6B137B2E-001A-4BFA-BDB2-7378CC903E62" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.38:*:*:*:*:*:*:*", "matchCriteriaId": "E857EA7F-6E7D-4619-9330-867C2A5381FD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.39:*:*:*:*:*:*:*", "matchCriteriaId": "14C3B4FD-1144-442F-9304-2676FEFAB583" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.40:*:*:*:*:*:*:*", "matchCriteriaId": "91F06131-5D63-4DF4-8D70-67892F327846" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ext2_filesystems_utilities:e2fsprogs:1.40.1:*:*:*:*:*:*:*", "matchCriteriaId": "18FCB21D-8D93-4F19-BCFC-3861C5A8DB5F" } ] } ] } ], "references": [ { "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083", "source": "secalert@redhat.com" }, { "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083", "source": "secalert@redhat.com" }, { "url": "http://lists.vmware.com/pipermail/security-announce/2008/000007.html", "source": "secalert@redhat.com" }, { "url": "http://secunia.com/advisories/27889", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/27965", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/27987", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/28000", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/28030", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/28042", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/28360", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/28541", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/28648", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/29224", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/32774", "source": "secalert@redhat.com" }, { "url": "http://secunia.com/advisories/40551", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://sourceforge.net/project/shownotes.php?release_id=560230&group_id=2406", "source": "secalert@redhat.com" }, { "url": "http://support.avaya.com/elmodocs2/security/ASA-2008-040.htm", "source": "secalert@redhat.com" }, { "url": "http://support.citrix.com/article/CTX118766", "source": "secalert@redhat.com" }, { "url": "http://wiki.rpath.com/Advisories:rPSA-2007-0262", "source": "secalert@redhat.com" }, { "url": "http://www.debian.org/security/2007/dsa-1422", "source": "secalert@redhat.com" }, { "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:242", "source": "secalert@redhat.com" }, { "url": "http://www.novell.com/linux/security/advisories/2007_25_sr.html", "source": "secalert@redhat.com" }, { "url": "http://www.redhat.com/support/errata/RHSA-2008-0003.html", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/archive/1/487999/100/0/threaded", "source": "secalert@redhat.com" }, { "url": "http://www.securityfocus.com/archive/1/489082/100/0/threaded", "source": "secalert@redhat.com" }, { "url": "http://www.securityfocus.com/bid/26772", "source": "secalert@redhat.com" }, { "url": "http://www.securitytracker.com/id?1019537", "source": "secalert@redhat.com" }, { "url": "http://www.ubuntu.com/usn/usn-555-1", "source": "secalert@redhat.com" }, { "url": "http://www.vmware.com/security/advisories/VMSA-2008-0004.html", "source": "secalert@redhat.com" }, { "url": "http://www.vupen.com/english/advisories/2007/4135", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.vupen.com/english/advisories/2008/0761", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.vupen.com/english/advisories/2010/1796", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/38903", "source": "secalert@redhat.com" }, { "url": "https://issues.rpath.com/browse/RPL-2011", "source": "secalert@redhat.com" }, { "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10399", "source": "secalert@redhat.com" }, { "url": "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00618.html", "source": "secalert@redhat.com" }, { "url": "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00629.html", "source": "secalert@redhat.com" }, { "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://lists.vmware.com/pipermail/security-announce/2008/000007.html", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://secunia.com/advisories/27889", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/27965", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/27987", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/28000", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/28030", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/28042", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/28360", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/28541", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/28648", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/29224", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/32774", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://secunia.com/advisories/40551", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://sourceforge.net/project/shownotes.php?release_id=560230&group_id=2406", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://support.avaya.com/elmodocs2/security/ASA-2008-040.htm", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://support.citrix.com/article/CTX118766", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://wiki.rpath.com/Advisories:rPSA-2007-0262", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.debian.org/security/2007/dsa-1422", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:242", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.novell.com/linux/security/advisories/2007_25_sr.html", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.redhat.com/support/errata/RHSA-2008-0003.html", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/archive/1/487999/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.securityfocus.com/archive/1/489082/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.securityfocus.com/bid/26772", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.securitytracker.com/id?1019537", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.ubuntu.com/usn/usn-555-1", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.vmware.com/security/advisories/VMSA-2008-0004.html", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.vupen.com/english/advisories/2007/4135", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.vupen.com/english/advisories/2008/0761", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.vupen.com/english/advisories/2010/1796", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/38903", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://issues.rpath.com/browse/RPL-2011", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10399", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00618.html", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00629.html", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }