CVE-2010-3879

Publication date 3 December 2010

Last updated 24 July 2024


Ubuntu priority

FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.

Read the notes from the security team

Status

Package Ubuntu Release Status
fuse 10.10 maverick
Fixed 2.8.4-1ubuntu1.1
10.04 LTS lucid
Fixed 2.8.1-1.1ubuntu2.2
9.10 karmic
Fixed 2.7.4-1.1ubuntu4.4
8.04 LTS hardy
Fixed 2.7.2-1ubuntu2.2
6.06 LTS dapper Ignored end of life
util-linux 10.10 maverick
Fixed 2.17.2-0ubuntu1.10.10.1
10.04 LTS lucid
Fixed 2.17.2-0ubuntu1.10.04.1
9.10 karmic
Fixed 2.16-1ubuntu5.1
8.04 LTS hardy
Fixed 2.13.1-5ubuntu3.1
6.06 LTS dapper Ignored end of life

Notes


mdeslaur

will also need to patch util-linux to get --no-canonicalize See novell bug for a bunch of commits, and new patches util-linux negligible (update only needed for fuse)

References

Related Ubuntu Security Notices (USN)

Other references