Vulnerability Name:

CVE-2005-1858 (CCN-20882)

Assigned:2005-06-03
Published:2005-06-03
Updated:2008-09-05
Summary:FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: CONFIRM
Type: Vendor Advisory
http://bugs.debian.org/311634

Source: MITRE
Type: CNA
CVE-2005-1858

Source: CCN
Type: FUSE Web site
FUSE: Filesystem in Userspace

Source: CCN
Type: SA15561
FUSE Exposure of Sensitive Information

Source: SECUNIA
Type: Patch, Vendor Advisory
15561

Source: SECUNIA
Type: UNKNOWN
16024

Source: CCN
Type: SECTRACK ID: 1014107
Filesystem in Userspace (FUSE) May Disclose Information to Local Users

Source: SECTRACK
Type: UNKNOWN
1014107

Source: CONFIRM
Type: Vendor Advisory
http://sourceforge.net/project/shownotes.php?release_id=331884

Source: DEBIAN
Type: UNKNOWN
DSA-744

Source: DEBIAN
Type: DSA-744
fuse -- programming error

Source: OSVDB
Type: Vendor Advisory
17042

Source: CCN
Type: OSVDB ID: 17042
FUSE Malformed Read Request Arbitrary Kernel Memory Disclosure

Source: BID
Type: UNKNOWN
13857

Source: CCN
Type: BID-13857
FUSE Local Information Disclosure Vulnerability

Source: MISC
Type: Vendor Advisory
http://www.sven-tantau.de/public_files/fuse/fuse_20050603.txt

Source: XF
Type: UNKNOWN
fuse-memory-information-disclosure(20882)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:fuse:fuse:2.2:*:*:*:*:*:*:*
  • OR cpe:/a:fuse:fuse:2.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:fuse:fuse:2.3_pre:*:*:*:*:*:*:*
  • OR cpe:/a:fuse:fuse:2.3_rc1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:fuse:fuse:2.2:*:*:*:*:*:*:*
  • OR cpe:/a:fuse:fuse:2.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:fuse:fuse:2.3:rc1:*:*:*:*:*:*
  • AND
  • cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.debian:def:744
    V
    programming error
    2005-07-08
    BACK
    fuse fuse 2.2
    fuse fuse 2.2.1
    fuse fuse 2.3_pre
    fuse fuse 2.3_rc1
    fuse fuse 2.2
    fuse fuse 2.2.1
    fuse fuse 2.3 rc1
    debian debian linux 3.1