e2fsprogs multiple integer overflows
Published Dec 7, 2007
5.8
MEDIUMCVSS 2.0
EPSS 4.11%
Description
Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image.
Affected products
No data.
- ≤ 1.40.2
- 1.02
- 1.03
- 1.04
- 1.05
- 1.06
- 1.07
- 1.08
- 1.09
- 1.10
- 1.11
- 1.12
- 1.13
- 1.14
- 1.15
- 1.16
- 1.17
- 1.18
- 1.19
- 1.20
- 1.21
- 1.22
- 1.23
- 1.24
- 1.25
- 1.26
- 1.27
- 1.28
- 1.29
- 1.30
- 1.31
- 1.32
- 1.33
- 1.34
- 1.35
- 1.36
- 1.37
- 1.38
- 1.39
- 1.40
- 1.40.1
No data.
Red Hat Enterprise Linux 2.1
e2fsprogs-0:1.26-1.73
Fixed · RHSA-2008:0003
Red Hat Enterprise Linux 3
e2fsprogs-0:1.32-15.4
Fixed · RHSA-2008:0003
Red Hat Enterprise Linux 4
e2fsprogs-0:1.35-12.11.el4_6.1
Fixed · RHSA-2008:0003
Red Hat Enterprise Linux 5
e2fsprogs-0:1.39-10.el5_1.1
Fixed · RHSA-2008:0003
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | e2fsprogs-0:1.26-1.73 | Fixed | RHSA-2008:0003 |
| Red Hat Enterprise Linux 3 | e2fsprogs-0:1.32-15.4 | Fixed | RHSA-2008:0003 |
| Red Hat Enterprise Linux 4 | e2fsprogs-0:1.35-12.11.el4_6.1 | Fixed | RHSA-2008:0003 |
| Red Hat Enterprise Linux 5 | e2fsprogs-0:1.39-10.el5_1.1 | Fixed | RHSA-2008:0003 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.11% (0.04105) | 90.44th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.98% (0.03978) | 89.11th | v5 (v2026.06.15) |
| Apr 8, 2026 | 2.99% (0.02986) | 86.52th | v4 (v2025.03.14) |
| Mar 25, 2026 | 4.33% (0.04328) | 88.83th | v4 (v2025.03.14) |
| Mar 30, 2025 | 7.51% (0.07514) | 90.96th | v4 (v2025.03.14) |
| Mar 29, 2025 | 20.62% (0.20620) | 92.80th | v4 (v2025.03.14) |
| Mar 19, 2025 | 8.21% (0.08207) | 91.14th | v4 (v2025.03.14) |
| Mar 17, 2025 | 6.03% (0.06031) | 90.02th | v4 (v2025.03.14) |
| Dec 25, 2024 | 8.13% (0.08133) | 94.33th | v3 (v2023.03.01) |
| Dec 17, 2024 | 11.07% (0.11070) | 95.12th | v3 (v2023.03.01) |
| Dec 12, 2024 | 13.05% (0.13047) | 95.75th | v3 (v2023.03.01) |
| Oct 10, 2024 | 12.56% (0.12556) | 95.57th | v3 (v2023.03.01) |
| Sep 2, 2024 | 9.97% (0.09973) | 94.98th | v3 (v2023.03.01) |
| Jul 26, 2024 | 12.22% (0.12219) | 95.45th | v3 (v2023.03.01) |
| May 10, 2024 | 14.23% (0.14228) | 95.68th | v3 (v2023.03.01) |
| Apr 2, 2024 | 6.54% (0.06538) | 93.62th | v3 (v2023.03.01) |
| Feb 26, 2024 | 4.56% (0.04557) | 92.25th | v3 (v2023.03.01) |
| Jan 19, 2024 | 3.21% (0.03207) | 90.24th | v3 (v2023.03.01) |
| Dec 13, 2023 | 3.34% (0.03337) | 90.33th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.09% (0.03092) | 89.50th | v3 (v2023.03.01) |
| Mar 6, 2023 | 9.92% (0.09915) | 94.52th | v2 (v2022.01.01) |
| Feb 13, 2023 | 9.92% (0.09915) | 94.33th | v2 (v2022.01.01) |
| Feb 3, 2023 | 2.69% (0.02686) | 82.44th | v2 (v2022.01.01) |
| Apr 1, 2022 | 9.92% (0.09915) | 94.04th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.92% (0.09915) | 87.53th | v2 (v2022.01.01) |
References (40)
- http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083 vendor-advisoryx_refsource_HP
- http://lists.vmware.com/pipermail/security-announce/2008/000007.html mailing-listx_refsource_MLIST
- http://secunia.com/advisories/27889 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27965 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27987 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28000 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28030 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28042 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28360 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28541 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28648 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29224 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/32774 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/40551 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=560230&group_id=2406 x_refsource_CONFIRM
- http://support.avaya.com/elmodocs2/security/ASA-2008-040.htm x_refsource_CONFIRM
- http://support.citrix.com/article/CTX118766 x_refsource_CONFIRM
- http://wiki.rpath.com/Advisories:rPSA-2007-0262 x_refsource_CONFIRM
- http://www.debian.org/security/2007/dsa-1422 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:242 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2007_25_sr.html vendor-advisoryx_refsource_SUSE
- http://www.redhat.com/support/errata/RHSA-2008-0003.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.securityfocus.com/archive/1/487999/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/489082/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/26772 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1019537 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/usn-555-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vmware.com/security/advisories/VMSA-2008-0004.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2007/4135 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2008/0761 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/1796 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2007-5497 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=403441 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38903 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-2011 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2007-5497
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10399 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-5497
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00618.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00629.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.