PT-2011-1122 · Red Hat · Fuse+2
Josh Bressers
·
Published
2011-07-20
·
Updated
2023-02-13
·
CVE-2011-0543
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
fuse versions 2.8.3 through 2.8.5
fuse-devel version 2.8.3
fuse-libs version 2.8.3
fuse-debuginfo version 2.8.3
Description
The issue concerns multiple vulnerabilities in the fuse package of Red Hat Enterprise Linux, which can be exploited remotely to compromise the integrity and availability of protected information. Local users can bypass intended access restrictions and unmount arbitrary directories via a symlink attack when util-linux does not support the --no-canonicalize option.
Recommendations
For fuse versions 2.8.3 through 2.8.5, consider updating to a version later than 2.8.5 to resolve the issue.
For fuse-devel version 2.8.3, update to a newer version to mitigate the risk.
For fuse-libs version 2.8.3, update to a newer version to mitigate the risk.
For fuse-debuginfo version 2.8.3, update to a newer version to mitigate the risk.
As a temporary workaround, consider restricting access to the fusermount functionality in fuse until a patch is available.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Fuse
Util-Linux