Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2005:216: fuse Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the fuse package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2005:216 (fuse).
Thomas Beige found that fusermount failed to securely handle special characters
specified in mount points, which could allow a local attacker to corrupt the
contents of /etc/mtab by mounting over a maliciously-named directory using
fusermount. This could potentially allow the attacker to set unauthorized mount
options. This is only possible when fusermount is installed setuid root, which
is the case in Mandriva Linux. The updated packages have been patched to
address these problems.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:216
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.