PT-2005-1094 · Filesystem In Userspace · Fuse

Thomas Biege

·

Publicado

2005-11-22

·

Atualizado

2011-03-08

·

CVE-2005-3531

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FUSE versions prior to 2.4.1
Description The issue allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters. This can lead to a violation of protected information integrity. The exploitation of this issue can be carried out locally.
Recommendations For versions prior to 2.4.1, update to version 2.4.1 or later to resolve the issue. As a temporary workaround, consider removing the setuid root bit from fusermount to prevent local users from exploiting this issue. Restrict access to fusermount to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-09487
CVE-2005-3531
DTSA-27-1

Produtos afetados

Fuse