CVE-2010-3879
Publication date 3 December 2010
Last updated 24 July 2024
Ubuntu priority
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
Status
Package | Ubuntu Release | Status |
---|---|---|
fuse | ||
util-linux | ||
Notes
mdeslaur
will also need to patch util-linux to get --no-canonicalize See novell bug for a bunch of commits, and new patches util-linux negligible (update only needed for fuse)
References
Related Ubuntu Security Notices (USN)
- USN-1045-2
- util-linux update
- 19 January 2011
- USN-1045-1
- FUSE vulnerability
- 19 January 2011