CVE-2019-5094

Source
https://cve.org/CVERecord?id=CVE-2019-5094
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5094.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-5094
Downstream
Related
Published
2019-09-24T22:15:13.247Z
Modified
2026-03-15T22:29:39.458703Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

References

Affected packages

Git / github.com/tytso/e2fsprogs

Affected ranges

Type
GIT
Repo
https://github.com/tytso/e2fsprogs
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.43.3"
        },
        {
            "last_affected": "1.45.3"
        }
    ]
}

Affected versions

1.*
1.43.4
debian/1.*
debian/1.44.3-1
v1.*
v1.43.3
v1.43.4
v1.43.5
v1.43.6
v1.43.7
v1.43.8
v1.43.9
v1.44.0
v1.44.0-rc1
v1.44.0-rc2
v1.44.1
v1.44.2
v1.44.3
v1.44.3-rc1
v1.44.3-rc2
v1.44.4
v1.44.5
v1.44.6
v1.45.0
v1.45.1
v1.45.1-rc1
v1.45.2
v1.45.3

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "8.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "9.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "10.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "30"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "31"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "12.04"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "14.04"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "16.04"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "18.04"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "19.04"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5094.json"