Title : Debian Security Update Fixes E2fsprogs libext2fs Integer Overflow Issues VUPEN ID : VUPEN/ADV-2007-4136 CVE ID : CVE-2007-5497
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-10
Technical Description
Multiple vulnerabilities have been idenitified in Debian, which could be exploited by attackers to cause a denial of service or execute arbitrary code. These issues are caused by errors in e2fsprogs. For additional information, see : VUPEN/ADV-2007-4135
Debian GNU/Linux etch - Upgrade to e2fsprogs version 1.39+1.40-WIP-2006.11.14+dfsg-2etch1
Debian GNU/Linux sid - A fix will be available soon. References