Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3202

Опубликовано: 02 июл. 2015
Источник: debian

Описание

fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
fusefixed2.9.3-16package
ntfs-3gfixed1:2014.2.15AR.3-3package

Примечания

  • Upstream fix: http://web.archive.org/web/20150529051222/http://sourceforge.net:80/p/fuse/fuse/ci/fe2d96

  • ntfs-3g source wise affected but wheezy version uses --with-fuse=external

  • ntfs-3g is built with internal copy since 1:2013.1.13AR.3-2

Связанные уязвимости

ubuntu
больше 10 лет назад

fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.

redhat
больше 10 лет назад

fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.

nvd
больше 10 лет назад

fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.

suse-cvrf
больше 10 лет назад

Security update for fuse

suse-cvrf
больше 10 лет назад

Security update for FUSE