|
|
>> Mandriva Security Update Fixes FUSE Local File Corruption Vulnerability
|
Title : Mandriva Security Update Fixes FUSE Local File Corruption Vulnerability VUPEN ID : VUPEN/ADV-2005-2576 CVE ID : CVE-2005-3531
Rated as : Low Risk 
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2005-11-25
|
Mandriva has released updated packages to correct a vulnerability identified in FUSE. This flaw is due to an error in "fusermount" that does not properly handle specially crafted directory names, which could be exploited by local attackers to corrupt the contents of the "/etc/mtab" file by mounting a malicious directory using fusermount. For additional information, see : VUPEN/ADV-2005-2529
Affected Products
Mandriva Linux 2006.0
Solution
Upgrade the affected packages :
Mandriva Linux 2006.0:
a3ae4ac8ed8a96214bbe1801722fd68e 2006.0/RPMS/dkms-fuse-2.3.0-2.1.20060mdk.i586.rpm
7703d6d4e053663bfa3712a6302c07be 2006.0/RPMS/fuse-2.3.0-2.1.20060mdk.i586.rpm
4daead454fd46fb8ea95953d9a1d3b12 2006.0/RPMS/libfuse2-2.3.0-2.1.20060mdk.i586.rpm
db457d4c29b4d8d19d34434086e12fc7 2006.0/RPMS/libfuse2-devel-2.3.0-2.1.20060mdk.i586.rpm
86880673c11a93aa8a9001d79416f962 2006.0/RPMS/libfuse2-static-devel-2.3.0-2.1.20060mdk.i586.rpm
88ec22000581f550f0f2c11f29e70b0c 2006.0/SRPMS/fuse-2.3.0-2.1.20060mdk.src.rpm
Mandriva Linux 2006.0/X86_64:
c94bfcb85845fd023fd2edfe88af55a4 x86_64/2006.0/RPMS/dkms-fuse-2.3.0-2.1.20060mdk.x86_64.rpm
bbbfc58364a1ceaeb363428e1cd9423c x86_64/2006.0/RPMS/fuse-2.3.0-2.1.20060mdk.x86_64.rpm
5b0cd9cef709bfcf624b35880c5fab46 x86_64/2006.0/RPMS/lib64fuse2-2.3.0-2.1.20060mdk.x86_64.rpm
80ba54b4cb2467f9d2045114fa859873 x86_64/2006.0/RPMS/lib64fuse2-devel-2.3.0-2.1.20060mdk.x86_64.rpm
8aa436b1cb28f893fd68ba2fa53ae76e x86_64/2006.0/RPMS/lib64fuse2-static-devel-2.3.0-2.1.20060mdk.x86_64.rpm
88ec22000581f550f0f2c11f29e70b0c x86_64/2006.0/SRPMS/fuse-2.3.0-2.1.20060mdk.src.rpm
References
http://www.vupen.com/english/advisories/2005/2576 http://www.frsirt.com/english/reference/1354
ChangeLog
2005-11-25 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|