CVE-2019-5094

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-5094
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5094.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-5094
Downstream
Related
Published
2019-09-24T22:15:13Z
Modified
2025-10-14T17:04:15.428934Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

References

Affected packages

Git / github.com/tytso/e2fsprogs

Affected ranges

Type
GIT
Repo
https://github.com/tytso/e2fsprogs
Events

Affected versions

1.*

1.43.4

debian/1.*

debian/1.44.3-1

v1.*

v1.43.3
v1.43.4
v1.43.5
v1.43.6
v1.43.7
v1.43.8
v1.43.9
v1.44.0
v1.44.0-rc1
v1.44.0-rc2
v1.44.1
v1.44.2
v1.44.3
v1.44.3-rc1
v1.44.3-rc2
v1.44.4
v1.44.5
v1.44.6
v1.45.0
v1.45.1
v1.45.1-rc1
v1.45.2
v1.45.3