Debian Security Advisory
DSA-4257-1 fuse -- security update
- Date Reported:
- 28 Jul 2018
- Affected Packages:
- fuse
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 904439.
In Mitre's CVE dictionary: CVE-2018-10906. - More information:
-
Jann Horn discovered that FUSE, a Filesystem in USErspace, allows the bypass of the
user_allow_other
restriction when SELinux is active (including in permissive mode). A local user can take advantage of this flaw in the fusermount utility to bypass the system configuration and mount a FUSE filesystem with theallow_other
mount option.For the stable distribution (stretch), this problem has been fixed in version 2.9.7-1+deb9u1.
We recommend that you upgrade your fuse packages.
For the detailed security status of fuse please refer to its security tracker page at: https://security-tracker.debian.org/tracker/fuse