PT-2011-1120 · Red Hat · Fuse-Debuginfo+4

Josh Bressers

·

Published

2011-07-20

·

Updated

2024-06-15

·

CVE-2011-0541

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions fuse versions 2.8.3 and earlier fuse-devel versions 2.8.3 and earlier fuse-libs versions 2.8.3 and earlier fuse-debuginfo versions 2.8.3 and earlier
Description The issue concerns multiple vulnerabilities in the fuse package of Red Hat Enterprise Linux, which can lead to the disruption of integrity and availability of protected information. These vulnerabilities can be exploited remotely. Additionally, a local user can unmount arbitrary directories via a symlink attack when /etc/mtab cannot be updated.
Recommendations For fuse versions 2.8.3 and earlier, consider updating to a version later than 2.8.5 to resolve the issue. For fuse-devel versions 2.8.3 and earlier, consider updating to a version later than 2.8.5 to resolve the issue. For fuse-libs versions 2.8.3 and earlier, consider updating to a version later than 2.8.5 to resolve the issue. For fuse-debuginfo versions 2.8.3 and earlier, consider updating to a version later than 2.8.5 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable package to minimize the risk of exploitation.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06658
BDU:2015-06659
BDU:2015-06660
BDU:2015-06661
CVE-2011-0541
OPENSUSE-SU-2024:10378-1
RHSA-2011:1083
RHSA-2011_1083

Affected Products

Red Hat
Fuse
Fuse-Debuginfo
Fuse-Devel
Fuse-Libs