[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3266-1 fuse -- fuse

ID: oval:org.secpod.oval:def:602113Date: (C)2015-06-04   (M)2022-09-22
Class: PATCHFamily: unix




Tavis Ormandy discovered that FUSE, a Filesystem in USErspace, does not scrub the environment before executing mount or umount with elevated privileges. A local user can take advantage of this flaw to overwrite arbitrary files and gain elevated privileges by accessing debugging features via the environment that would not normally be safe for unprivileged users.

Platform:
Debian 8.x
Debian 7.x
Product:
fuse
Reference:
DSA-3266-1
CVE-2015-3202
CVE    1
CVE-2015-3202
CPE    3
cpe:/a:fuse:fuse
cpe:/o:debian:debian_linux:7.x
cpe:/o:debian:debian_linux:8.x

© SecPod Technologies