[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3451-1 fuse -- fuse

ID: oval:org.secpod.oval:def:602345Date: (C)2016-01-29   (M)2021-09-11
Class: PATCHFamily: unix




Jann Horn discovered a vulnerability in the fuse package in Debian. The fuse package ships an udev rules adjusting permissions on the related /dev/cuse character device, making it world writable. This permits a local, unprivileged attacker to create an arbitrarily-named character device in /dev and modify the memory of any process that opens it and performs an ioctl on it. This in turn might allow a local, unprivileged attacker to escalate to root privileges.

Platform:
Debian 8.x
Product:
fuse
Reference:
DSA-3451-1
CVE-2016-1233
CVE    1
CVE-2016-1233
CPE    2
cpe:/a:fuse:fuse
cpe:/o:debian:debian_linux:8.x

© SecPod Technologies