Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1572
Reference (s):
- BID:72709
- URL: http://www.securityfocus.com/bid/72709
- http://advisories.mageia.org/MGASA-2015-0088.html
- https://git.kernel.org/cgit/fs/ext2/e2fsprogs.git/commit/?id=49d0fe2a14f2a23da2fe299643379b8c1d37df73
- DEBIAN:DSA-3166

