FUSE 本地信息泄露漏洞

漏洞信息详情

FUSE 本地信息泄露漏洞

漏洞简介

FUSE 2.3.0之前的2.x版本中,在文件系统对读请求返回一个短整型字节数时,无法从未满页面中正确清除以前使用过的内存,本地用户就可能利用此漏洞获得敏感信息。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Miklos Szeredi FUSE 2.2
Miklos Szeredi fuse-2.3.0.tar.gz
http://prdownloads.sourceforge.net/fuse/fuse-2.3.0.tar.gz?download
Miklos Szeredi FUSE 2.2.1
Debian fuse-source_2.2.1-4sarge2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/fuse-source_2.2.1- 4sarge2_all.deb
Debian fuse-utils_2.2.1-4sarge2_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/fuse-utils_2.2.1-4 sarge2_alpha.deb
Debian fuse-utils_2.2.1-4sarge2_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/fuse-utils_2.2.1-4 sarge2_amd64.deb
Debian fuse-utils_2.2.1-4sarge2_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/fuse-utils_2.2.1-4 sarge2_arm.deb
Debian fuse-utils_2.2.1-4sarge2_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/fuse-utils_2.2.1-4 sarge2_hppa.deb
Debian fuse-utils_2.2.1-4sarge2_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/fuse-utils_2.2.1-4 sarge2_i386.deb
Debian fuse-utils_2.2.1-4sarge2_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/fuse-utils_2.2.1-4 sarge2_ia64.deb
Debian fuse-utils_2.2.1-4sarge2_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/fuse-utils_2.2.1-4 sarge2_m68k.deb
Debian fuse-utils_2.2.1-4sarge2_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/fuse-utils_2.2.1-4 sarge2_mips.deb
Debian fuse-utils_2.2.1-4sarge2_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/fuse-utils_2.2.1-4 sarge2_mipsel.deb
Debian fuse-utils_2.2.1-4sarge2_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/fuse-utils_2.2.1-4 sarge2_powerpc.deb
Debian fuse-utils_2.2.1-4sarge2_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/fuse-utils_2.2.1-4 sarge2_s390.deb
Debian fuse-utils_2.2.1-4sarge2_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/fuse-utils_2.2.1-4 sarge2_sparc.deb
Debian libfuse-dev_2.2.1-4sarge2_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse-dev_2.2.1- 4sarge2_alpha.deb
Debian libfuse-dev_2.2.1-4sarge2_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse-dev_2.2.1- 4sarge2_amd64.deb
Debian libfuse-dev_2.2.1-4sarge2_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse-dev_2.2.1- 4sarge2_arm.deb
Debian libfuse-dev_2.2.1-4sarge2_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse-dev_2.2.1- 4sarge2_hppa.deb
Debian libfuse-dev_2.2.1-4sarge2_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse-dev_2.2.1- 4sarge2_i386.deb
Debian libfuse-dev_2.2.1-4sarge2_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse-dev_2.2.1- 4sarge2_ia64.deb
Debian libfuse-dev_2.2.1-4sarge2_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse-dev_2.2.1- 4sarge2_m68k.deb
Debian libfuse-dev_2.2.1-4sarge2_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse-dev_2.2.1- 4sarge2_mips.deb
Debian libfuse-dev_2.2.1-4sarge2_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse-dev_2.2.1- 4sarge2_mipsel.deb
Debian libfuse-dev_2.2.1-4sarge2_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse-dev_2.2.1- 4sarge2_powerpc.deb
Debian libfuse-dev_2.2.1-4sarge2_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse-dev_2.2.1- 4sarge2_s390.deb
Debian libfuse-dev_2.2.1-4sarge2_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse-dev_2.2.1- 4sarge2_sparc.deb
Debian libfuse2_2.2.1-4sarge2_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse2_2.2.1-4sa rge2_alpha.deb
Debian libfuse2_2.2.1-4sarge2_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse2_2.2.1-4sa rge2_amd64.deb
Debian libfuse2_2.2.1-4sarge2_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse2_2.2.1-4sa rge2_arm.deb
Debian libfuse2_2.2.1-4sarge2_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse2_2.2.1-4sa rge2_hppa.deb
Debian libfuse2_2.2.1-4sarge2_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse2_2.2.1-4sa rge2_i386.deb
Debian libfuse2_2.2.1-4sarge2_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse2_2.2.1-4sa rge2_ia64.deb
Debian libfuse2_2.2.1-4sarge2_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse2_2.2.1-4sa rge2_m68k.deb
Debian libfuse2_2.2.1-4sarge2_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse2_2.2.1-4sa rge2_mips.deb
Debian libfuse2_2.2.1-4sarge2_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse2_2.2.1-4sa rge2_mipsel.deb
Debian libfuse2_2.2.1-4sarge2_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse2_2.2.1-4sa rge2_powerpc.deb
Debian libfuse2_2.2.1-4sarge2_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse2_2.2.1-4sa rge2_s390.deb
Debian libfuse2_2.2.1-4sarge2_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fuse/libfuse2_2.2.1-4sa rge2_sparc.deb
Miklos Szeredi fuse-2.3.0.tar.gz
http://prdownloads.sourceforge.net/fuse/fuse-2.3.0.tar.gz?download

参考网址

来源: SECUNIA
名称: 15561
链接:http://secunia.com/advisories/15561/

来源: MISC
链接:http://www.sven-tantau.de/public_files/fuse/fuse_20050603.txt

来源: BID
名称: 13857
链接:http://www.securityfocus.com/bid/13857

来源: OSVDB
名称: 17042
链接:http://www.osvdb.org/17042

来源: sourceforge.net
链接:http://sourceforge.net/project/shownotes.php?release_id=331884

来源: bugs.debian.org
链接:http://bugs.debian.org/311634

来源: DEBIAN
名称: DSA-744
链接:http://www.debian.org/security/2005/dsa-744

来源: SECTRACK
名称: 1014107
链接:http://securitytracker.com/id?1014107

来源: SECUNIA
名称: 16024
链接:http://secunia.com/advisories/16024

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享