fuse: privilege escalation
| Package(s): | fuse |
CVE #(s): | CVE-2016-1233
|
| Created: | January 22, 2016 |
Updated: | January 27, 2016 |
| Description: |
From the Debian advisory:
Jann Horn discovered a vulnerability in the fuse (Filesystem in
Userspace) package in Debian. The fuse package ships an udev rules
adjusting permissions on the related /dev/cuse character device, making
it world writable.
This permits a local, unprivileged attacker to create an
arbitrarily-named character device in /dev and modify the memory of any
process that opens it and performs an ioctl on it.
This in turn might allow a local, unprivileged attacker to escalate to
root privileges. |
| Alerts: |
|