French Security Incident Response Team

FrSIRT   

      

   français French  anglais English

 
Vulnerability Notification Service
FrSIRT Partner Program
14-Day Free Trial
Contact FrSIRT Sales Dept.
 

Security Advisories
Linux Security Advisories
Virus and Threats Advisories
Latest Security News
Latest Zero Day Threats
Advisories and vulnerabilities by Vendor
Advisories and vulnerabilities by Keyword
 

Report a security incident
Report a new vulnerability
Security Mailinglist
 

Our Company
FrSIRT in the News
Advertise on FrSIRT.COM
Security Researchers and Exploit Writers Jobs
Contact Us

Fedora Security Update Fixes E2fsprogs libext2fs Integer Overflow Issues


Title : Fedora Security Update Fixes E2fsprogs libext2fs Integer Overflow Issues
Advisory ID : FrSIRT/ADV-2008-0208
CVE ID : CVE-2007-5497
Rated as : Low Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2008-01-21

Advisory Details

 
  Description
  Affected Products
  Solution
  References
Technical Description    Receive FrSIRT alerts in a Text format  Receive FrSIRT alerts in a PDF format  Receive FrSIRT alerts in an XML format  Receive FrSIRT notifications by SMS 

Multiple vulnerabilities have been idenitified in Fedora, which could be exploited by attackers to cause a denial of service or execute arbitrary code [...]

Solution

Upgrade the affected packages :

f46f6a669d933d8d0d3c31ace0287fc270579097 e2fsprogs-libs-1.40.2-3.fc7.ppc64.rpm
62dfdf0bc8d4ab4edff3b10008bb04fee3dbfafb e2fsprogs-debuginfo-1.40.2-3.fc7.ppc64.rpm
1128e9bdb19a8d5bc05ac40e811217478dd22f0f e2fsprogs-1.40.2-3.fc7.ppc64.rpm
4903f9728fd5840b92bc35f3acbad46c032e461c e2fsprogs-devel-1.40.2-3.fc7.ppc64.rpm
fe6389dbea4cf72d75c8c67f4d77286f5f37dc49 e2fsprogs-libs-1.40.2-3.fc7.i386.rpm
f7734510507e698f3d355acef291dd7c8ed6625a e2fsprogs-debuginfo-1.40.2-3.fc7.i386.rpm
d0eb54ab2456b49ceb341b9fb44b4ed6924584db e2fsprogs-1.40.2-3.fc7.i386.rpm
12cddf031d6cdd5ab684d04b40467ac05e3862d0 e2fsprogs-devel-1.40.2-3.fc7.i386.rpm
4cbfcc13800d1edc4d8361f403fdacb1708136d9 e2fsprogs-1.40.2-3.fc7.x86_64.rpm
4197ddd309dc4aa1017feae11e7e2dfad9bbb9de e2fsprogs-libs-1.40.2-3.fc7.x86_64.rpm
1319deff60ac4ff99d78e807919729641388d468 e2fsprogs-devel-1.40.2-3.fc7.x86_64.rpm
b01f7afaebd39fb251636265eb6a239b266e62b7 e2fsprogs-debuginfo-1.40.2-3.fc7.x86_64.rpm
b71e3d93ccf4282c347d2b08df1e205325907777 e2fsprogs-1.40.2-3.fc7.ppc.rpm
35ff781cc498a1d0043a89e4ea3ef31f5bbf29d4 e2fsprogs-libs-1.40.2-3.fc7.ppc.rpm
3a50a0f1a8f417d77cc9a0a59822f23edf909e5d e2fsprogs-devel-1.40.2-3.fc7.ppc.rpm
f70cb377b4c9d44c667d28f9c5ce20af425e321d e2fsprogs-debuginfo-1.40.2-3.fc7.ppc.rpm
106125f3450cfb5029563e84e3cae6a7f1c2d588 e2fsprogs-1.40.2-3.fc7.src.rpm

776310be2583d7f805408c9b0419c11f60677b5f e2fsprogs-debuginfo-1.40.2-12.fc8.ppc64.rpm
0dcbd3e2c6d9e66a9c04d5f0955cba78406fbf44 e2fsprogs-1.40.2-12.fc8.ppc64.rpm
ff4f44a50ac774b6463c15c58a0e3677d7fc0642 e2fsprogs-devel-1.40.2-12.fc8.ppc64.rpm
77a3495070753a018772f166b5557feca2a2aeec e2fsprogs-libs-1.40.2-12.fc8.ppc64.rpm
736d09c28f3e1a6a6c25d853f73f5cf38a5533f4 e2fsprogs-devel-1.40.2-12.fc8.i386.rpm
5b326984fec5e1afa59cea059fe5c098b4a96a5c e2fsprogs-1.40.2-12.fc8.i386.rpm
9066d4a84003d35ff52daefe754c1fafdd057787 e2fsprogs-debuginfo-1.40.2-12.fc8.i386.rpm
7ea9bdde09a650c2ad95f427d4ed402f44ccfc92 e2fsprogs-libs-1.40.2-12.fc8.i386.rpm
ce07543f85739042f9e0a998538d8a7f4ac037f9 e2fsprogs-1.40.2-12.fc8.x86_64.rpm
513351566c440f69d05c7f34200517ead541c09f e2fsprogs-libs-1.40.2-12.fc8.x86_64.rpm
22ffa76abebd5a7963285946210bb9760d5ed797 e2fsprogs-devel-1.40.2-12.fc8.x86_64.rpm
a607ee8151f73d0b6849d4756661fa1a0a828ed8 e2fsprogs-debuginfo-1.40.2-12.fc8.x86_64.rpm
f8ce4302db338f25e8fdbd022c664f970c792737 e2fsprogs-devel-1.40.2-12.fc8.ppc.rpm
7ad1cc5a4389a5c8c174244f9f979a6a68f98996 e2fsprogs-libs-1.40.2-12.fc8.ppc.rpm
f5746876daf9cb7b04af208be404714ca9cde83e e2fsprogs-debuginfo-1.40.2-12.fc8.ppc.rpm
c929b5cd5e11af5a7ab1ec6b61df1e71145ce261 e2fsprogs-1.40.2-12.fc8.ppc.rpm
6664b00c56f87d7a9e09bacd9b921eddea639fe1 e2fsprogs-1.40.2-12.fc8.src.rpm

ChangeLog

2008-01-21 : Initial release

Vulnerability Management

Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.


 
 

Search

      

Mailinglist

    
 

IBM AIX "swcons" Insecure Permission Privilege Escalation Vulnerability

IBM WebSphere Application Server Cross Site Scripting Vulnerability

IBM DB2 CLR Stored Procedures Unspecified Vulnerability

IBM Lotus Quickr Multiple Cross Site Scripting Vulnerabilities

IBM WebSphere Portal Remote Authentication Bypass Vulnerability

IBM Rational ClearQuest Login Page Cross Site Scripting Vulnerability

IBM WebSphere Application Server Security Exposure Vulnerabilities

Sun Solaris Covert Channel Local Security Bypass Vulnerability

Sun Solaris NFS RPC Zone Denial of Service Vulnerability

Sun Solaris NFS Kernel Module Local Denial of Service Vulnerability

Sun Solaris NFSv4 Client Kernel Module Denial of Service Vulnerability

Sun Java System Portal Server Cross Site Scripting Vulnerability

Sun rdesktop Code Execution and Denial of Service

Sun Java System Web Proxy Server Denial of Service Vulnerability

Mozilla Firefox for Mac OS X GIF Rendering Code Execution Vulnerability

Mozilla Products Remote Code Execution and Security Bypass Issues

Mozilla Products Code Execution and Injection Vulnerabilities

Mozilla JavaScript Garbage Collector Code Execution Vulnerability

Mozilla Thunderbird Code Execution and Cross Site Scripting Issues

Mozilla Firefox and SeaMonkey Multiple Remote Code Execution Issues

Mozilla Thunderbird Multiple Security Bypass and Code Execution Issues

Copyright 2003-2008 © FrSIRT.COM - Privacy Policy