Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-0541

Опубликовано: 02 нояб. 2010
Источник: redhat
CVSS2: 2.6

Описание

fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.

Отчет

The Red Hat Security Response Team has rated this issue as having low security impact. On Red Hat Enterprise Linux 5 and 6, a user must be a member of the 'fuse' group in order to use FUSE. Due to the risks associated with fixing this bug on Red Hat Enterprise Linux 5, and because of the group restrictions in place, we currently have no plans to fix this flaw in Red Hat Enterprise Linux 5.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5fuseWill not fix
Red Hat Enterprise Linux 5util-linuxWill not fix
Red Hat Enterprise Linux 6util-linux-ngAffected
Red Hat Enterprise Linux 6fuseFixedRHSA-2011:108320.07.2011

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=651183fuse: unprivileged user can unmount arbitrary locations via symlink attack

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
почти 14 лет назад

fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.

nvd
почти 14 лет назад

fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.

debian
почти 14 лет назад

fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot ...

github
около 3 лет назад

fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.

oracle-oval
почти 14 лет назад

ELSA-2011-1083: fuse security update (MODERATE)

2.6 Low

CVSS2