#VU21329 Out-of-bounds write in E2fsprogs - CVE-2019-5094
Published: September 25, 2019
E2fsprogs
e2fsprogs.sourceforge.net
Description
The vulnerability allows a local user to escalate privileges on the vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in the quota file functionality. A local user can send a specially crafted xt4 partition, trigger out-of-bounds write on the heap and execute arbitrary code on the target system.
Note: An attacker can corrupt a partition to trigger this vulnerability.