Oval Definition:oval:com.redhat.rhsa:def:20111083
Revision Date:2011-07-20Version:649
Title:RHSA-2011:1083: fuse security update (Moderate)
Description:FUSE (Filesystem in Userspace) can implement a fully functional file system in a user-space program. These packages provide the mount utility, fusermount, the tool used to mount FUSE file systems.

  • Multiple flaws were found in the way fusermount handled the mounting and unmounting of directories when symbolic links were present. A local user in the fuse group could use these flaws to unmount file systems, which they would otherwise not be able to unmount and that were not mounted using FUSE, via a symbolic link attack. (CVE-2010-3879, CVE-2011-0541, CVE-2011-0542, CVE-2011-0543)

    Note: The util-linux-ng RHBA-2011:0699 update must also be installed to fully correct the above flaws.

    All users should upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-3879
    CVE-2010-3879
    CVE-2011-0541
    CVE-2011-0541
    CVE-2011-0542
    CVE-2011-0542
    CVE-2011-0543
    CVE-2011-0543
    RHSA-2011:1083
    RHSA-2011:1083-01
    RHSA-2011:1083-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • fuse is earlier than 0:2.8.3-3.el6_1
  • AND fuse is signed with Red Hat redhatrelease2 key
  • fuse-devel is earlier than 0:2.8.3-3.el6_1
  • AND fuse-devel is signed with Red Hat redhatrelease2 key
  • fuse-libs is earlier than 0:2.8.3-3.el6_1
  • AND fuse-libs is signed with Red Hat redhatrelease2 key
  • BACK