New Debian e2fsprogs 1.43.4-2+deb9u1A~4.3.4.201910011346 fixes: This update addresses the following issue: * An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability. (CVE-2019-5094)
--- mirror/ftp/4.3/unmaintained/4.3-0/source/e2fsprogs_1.43.4-2A~4.3.0.201801041304.dsc +++ apt/ucs_4.3-0-errata4.3-4/source/e2fsprogs_1.43.4-2+deb9u1A~4.3.4.201910010703.dsc @@ -1,8 +1,12 @@ -1.43.4-2A~4.3.0.201801041304 [Thu, 04 Jan 2018 13:04:36 +0100] Univention builddaemon <buildd@univention.de>: +1.43.4-2+deb9u1A~4.3.4.201910010703 [Tue, 01 Oct 2019 14:43:13 +0200] Univention builddaemon <buildd@univention.de>: * UCS auto build. The following patches have been applied to the original source package 0001-Fix-parallel-FTBFS 01_inode_reatio + +1.43.4-2+deb9u1 [Wed, 25 Sep 2019 19:17:45 -0400] Theodore Y. Ts'o <tytso@mit.edu>: + + * Fix CVE-2019-5094: potential buffer overrun in e2fsck (Closes: #941139) 1.43.4-2 [Tue, 31 Jan 2017 19:54:55 -0500] Theodore Y. Ts'o <tytso@mit.edu>: <http://10.200.17.11/4.3-4/#6241735721381683720>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.3-4] 0b9828f422 Bug #50299: e2fsprogs 1.43.4-2+deb9u1A~4.3.4.201910010703 doc/errata/staging/e2fsprogs.yaml | 15 +++++++++++++++ 1 file changed, 15 insertions(+)
<http://errata.software-univention.de/ucs/4.3/593.html>