|
|
Log in / Subscribe / Register

fuse: privilege escalation

Package(s):fuse CVE #(s):CVE-2016-1233
Created:January 22, 2016 Updated:January 27, 2016
Description: From the Debian advisory:

Jann Horn discovered a vulnerability in the fuse (Filesystem in Userspace) package in Debian. The fuse package ships an udev rules adjusting permissions on the related /dev/cuse character device, making it world writable. This permits a local, unprivileged attacker to create an arbitrarily-named character device in /dev and modify the memory of any process that opens it and performs an ioctl on it. This in turn might allow a local, unprivileged attacker to escalate to root privileges.

Alerts:
Debian DSA-3451-1 fuse 2016-01-21

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds