CVE-2019-5188: High severity ibm infosphere guardium z/os vulnerability
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
Other sources
E2fsprogs could allow a local authenticated attacker to execute arbitrary code on the system, caused by an out-of-bounds write in the directory rehashing function. By using a specially-crafted ext4 directory, an attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-5188?
CVE-2019-5188 is a code execution vulnerability in the directory rehashing functionality of E2fsprogs e2fsck 1.
How does CVE-2019-5188 affect IBM Security Guardium?
IBM Security Guardium versions up to 11.3 are affected by CVE-2019-5188.
Is Debian Debian Linux impacted by CVE-2019-5188?
Yes, Debian Debian Linux versions 8.0 and 9.0 are impacted by CVE-2019-5188.
What is the severity of CVE-2019-5188?
CVE-2019-5188 has a severity rating of 7.5 (high).
Where can I find more information about CVE-2019-5188?
You can find more information about CVE-2019-5188 at the following references: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/174075), [Link 2](https://www.ibm.com/support/pages/node/6455281), [Link 3](http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00004.html).