LWN.net Logo

FUSE: mtab corruption through fusermount

Package(s):fuse CVE #(s):CVE-2005-3531
Created:November 22, 2005 Updated:January 24, 2006
Description: Thomas Biege discovered that fusermount fails to securely handle special characters specified in mount points. A local attacker could corrupt the contents of the /etc/mtab file by mounting over a maliciously-named directory using fusermount, potentially allowing the attacker to set unauthorized mount options.
Alerts:
Debian-Testing DTSA-27-1 2006-01-20
Mandriva MDKSA-2005:216 2005-11-24
Gentoo 200511-17 2005-11-22

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds