Executive Summary

Summary
Title FUSE vulnerability
Informations
NameUSN-892-1First vendor Publication2010-01-28
VendorUbuntuLast vendor Modification2010-01-28
Severity (Vendor) N/ARevisionN/A

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:N/I:P/A:P)
Cvss Base Score3.3Attack RangeLocal
Cvss Impact Score4.9Attack ComplexityMedium
Cvss Expoit Score3.4AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
Ubuntu 9.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
fuse-utils 2.4.2-0ubuntu3.1

Ubuntu 8.04 LTS:
fuse-utils 2.7.2-1ubuntu2.1

Ubuntu 8.10:
fuse-utils 2.7.3-4ubuntu2.1

Ubuntu 9.04:
fuse-utils 2.7.4-1.1ubuntu4.0.9.04.1

Ubuntu 9.10:
fuse-utils 2.7.4-1.1ubuntu4.3

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

Ronald Volgers discovered that FUSE did not correctly check mount
locations. A local attacker, with access to use FUSE, could unmount
arbitrary locations, leading to a denial of service.


Original Source

Url : http://www.ubuntu.com/usn/USN-892-1

CWE : Common Weakness Enumeration

idName
CWE-59Improper Link Resolution Before File Access ('Link Following')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application25

Open Source Vulnerability Database (OSVDB)

idDescription
62376FUSE fusermount Unmount Operation Race Condition DoS