CVE-2010-3879
Publication date 3 December 2010
Last updated 24 July 2024
Ubuntu priority
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
Status
Package | Ubuntu Release | Status |
---|---|---|
fuse | 10.10 maverick |
Fixed 2.8.4-1ubuntu1.1
|
10.04 LTS lucid |
Fixed 2.8.1-1.1ubuntu2.2
|
|
9.10 karmic |
Fixed 2.7.4-1.1ubuntu4.4
|
|
8.04 LTS hardy |
Fixed 2.7.2-1ubuntu2.2
|
|
6.06 LTS dapper | Ignored end of life | |
util-linux | 10.10 maverick |
Fixed 2.17.2-0ubuntu1.10.10.1
|
10.04 LTS lucid |
Fixed 2.17.2-0ubuntu1.10.04.1
|
|
9.10 karmic |
Fixed 2.16-1ubuntu5.1
|
|
8.04 LTS hardy |
Fixed 2.13.1-5ubuntu3.1
|
|
6.06 LTS dapper | Ignored end of life |
Notes
mdeslaur
will also need to patch util-linux to get --no-canonicalize See novell bug for a bunch of commits, and new patches util-linux negligible (update only needed for fuse)
References
Related Ubuntu Security Notices (USN)
- USN-1045-2
- util-linux update
- 19 January 2011
- USN-1045-1
- FUSE vulnerability
- 19 January 2011