Out-of-bounds write in E2fsprogs - CVE-2019-5188

 

Out-of-bounds write in E2fsprogs - CVE-2019-5188

Published: January 8, 2020


Vulnerability identifier: #VU24078
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5188
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input in the directory rehashing functionality in "rehash.c" within the "mutate_name()" function. A local user can use a specially crafted ext4 directory, trigger out-of-bounds write on the stack and execute arbitrary code on the target system.


Affected software

E2fsprogs
Amazon Linux AMI
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Opensuse
Fedora
Ansible Automation Platform
e2fsprogs (Red Hat package)
e2fsprogs (Alpine package)
e2fsprogs
IBM QRadar Network Security
Data Computing Appliance (DCA)
Red Hat OpenShift Container Platform

How to mitigate CVE-2019-5188

Install updates from vendor's website.

E2fsprogs - update to 1.45.5
Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
e2fsprogs (Red Hat package) - update to 1.42.9-19.el7
e2fsprogs (Alpine package) - update to 1.44.2-r2
IBM QRadar Network Security - addressed in versions 5.4.0.13, 5.5.0.8
e2fsprogs - addressed in versions 1.44.6-2.fc30, 1.45.5-1.fc31
Data Computing Appliance (DCA) - update to 4.3.0.0
Red Hat OpenShift Container Platform - update to 4.3.40

External References

Related Security Bulletins