PT-2011-1120 · Red Hat · Fuse-Debuginfo+4
Josh Bressers
·
Publicado
2011-07-20
·
Atualizado
2024-06-15
·
CVE-2011-0541
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
fuse versions 2.8.3 and earlier
fuse-devel versions 2.8.3 and earlier
fuse-libs versions 2.8.3 and earlier
fuse-debuginfo versions 2.8.3 and earlier
Description
The issue concerns multiple vulnerabilities in the fuse package of Red Hat Enterprise Linux, which can lead to the disruption of integrity and availability of protected information. These vulnerabilities can be exploited remotely. Additionally, a local user can unmount arbitrary directories via a symlink attack when /etc/mtab cannot be updated.
Recommendations
For fuse versions 2.8.3 and earlier, consider updating to a version later than 2.8.5 to resolve the issue.
For fuse-devel versions 2.8.3 and earlier, consider updating to a version later than 2.8.5 to resolve the issue.
For fuse-libs versions 2.8.3 and earlier, consider updating to a version later than 2.8.5 to resolve the issue.
For fuse-debuginfo versions 2.8.3 and earlier, consider updating to a version later than 2.8.5 to resolve the issue.
As a temporary workaround, consider restricting access to the vulnerable package to minimize the risk of exploitation.
Correção
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Fuse
Fuse-Debuginfo
Fuse-Devel
Fuse-Libs