fuse-2.8.3-3.AXS4

エラータID: AXSA:2011--684:01

リリース日: 
2011/12/29 Thursday - 21:12
題名: 
fuse-2.8.3-3.AXS4
影響のあるチャネル: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

With FUSE it is possible to implement a fully functional filesystem in a userspace program. This package contains the FUSE userspace tools to mount a FUSE filesystem.
Security issues fixed with this release:
CVE-2010-3879
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
CVE-2011-0541
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
CVE-2011-0542
fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.
CVE-2011-0543
Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.

解決策: 

Update packages.

追加情報: 

From Asianux Server 4 SP1.

ダウンロード: 

SRPMS
  1. fuse-2.8.3-3.AXS4.src.rpm
    MD5: 61853388fc1c78e0e1fcc9475367eab4
    SHA-256: 3f9010855c7908baeb97ea5d73e4bd2da28f250e5bfab8c5936e25877a5d4399
    Size: 501.90 kB

Asianux Server 4 for x86
  1. fuse-2.8.3-3.AXS4.i686.rpm
    MD5: 3c3f1a0eb139f818ed95578e55cb707d
    SHA-256: d3bcbb6da8541dfc8fc52218aa288c6171a288d45e637bff43b4526f7d0f0015
    Size: 70.04 kB
  2. fuse-devel-2.8.3-3.AXS4.i686.rpm
    MD5: f61aa206ea5f62c731312c334776583f
    SHA-256: 803ead29d2c544e15cfe6efcd9d40a383dc91a278d972e7d43d89a56884de2d7
    Size: 31.01 kB
  3. fuse-libs-2.8.3-3.AXS4.i686.rpm
    MD5: 92cfa824a967b069efbce61edbc74383
    SHA-256: d4ea7e61e387a062da039ceab8e8ff0f7d327cec5794d00a83aa40a38d5d189d
    Size: 75.11 kB

Asianux Server 4 for x86_64
  1. fuse-2.8.3-3.AXS4.x86_64.rpm
    MD5: cec3389c9cddb817ec8c1440f0a9180d
    SHA-256: 8905e6e6ff961475465ad42a83807d3b5e5d8ac0f85f15b2346674f7b13842a8
    Size: 70.07 kB
  2. fuse-devel-2.8.3-3.AXS4.x86_64.rpm
    MD5: 55f831708e6ae1ed9781bba362520040
    SHA-256: 5be4df015233b3729088626138810c319cbc832560cf756ac355c2b86a4ec523
    Size: 30.59 kB
  3. fuse-libs-2.8.3-3.AXS4.x86_64.rpm
    MD5: 69eb580ea29f6a2c9d1a6d4ae6886a5d
    SHA-256: 83f02f57b2864dec77ad52b32105553ecf5757a815a97e2e092b12b7d2287e24
    Size: 73.21 kB
  4. fuse-devel-2.8.3-3.AXS4.i686.rpm
    MD5: f61aa206ea5f62c731312c334776583f
    SHA-256: 803ead29d2c544e15cfe6efcd9d40a383dc91a278d972e7d43d89a56884de2d7
    Size: 31.01 kB
  5. fuse-libs-2.8.3-3.AXS4.i686.rpm
    MD5: 92cfa824a967b069efbce61edbc74383
    SHA-256: d4ea7e61e387a062da039ceab8e8ff0f7d327cec5794d00a83aa40a38d5d189d
    Size: 75.11 kB