RSS   Vulnerabilities for 'FUSE'   RSS

2011-09-02
 
CVE-2011-0543

CWE-264
 

 
Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.

 
 
CVE-2011-0542

CWE-264
 

 
fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.

 
 
CVE-2011-0541

CWE-59
 

 
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.

 
2011-01-22
 
CVE-2010-3879

CWE-59
 

 
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.

 
2010-03-02
 
CVE-2010-0789

CWE-59
 

 
fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.

 
2005-06-03
 
CVE-2005-1858

 

 
FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.

 


Copyright 2024, cxsecurity.com

 

Back to Top