PT-2005-1094 · Filesystem In Userspace · Fuse
Thomas Biege
·
Publicado
2005-11-22
·
Atualizado
2011-03-08
·
CVE-2005-3531
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FUSE versions prior to 2.4.1
Description
The issue allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters. This can lead to a violation of protected information integrity. The exploitation of this issue can be carried out locally.
Recommendations
For versions prior to 2.4.1, update to version 2.4.1 or later to resolve the issue. As a temporary workaround, consider removing the setuid root bit from fusermount to prevent local users from exploiting this issue. Restrict access to fusermount to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Fuse