Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.120031
Kategorie:Amazon Linux Local Security Checks
Titel:Amazon Linux: Security Advisory (ALAS-2015-558)
Zusammenfassung:The remote host is missing an update for the 'fuse' package(s) announced via the ALAS-2015-558 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'fuse' package(s) announced via the ALAS-2015-558 advisory.

Vulnerability Insight:
It was discovered that fusermount failed to properly sanitize its environment before executing mount and umount commands. A local user could possibly use this flaw to escalate their privileges on the system.

Affected Software/OS:
'fuse' package(s) on Amazon Linux.

Solution:
Please install the updated package(s).

CVSS Score:
3.6

CVSS Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2015-3202
1032386
http://www.securitytracker.com/id/1032386
37089
https://www.exploit-db.com/exploits/37089/
74765
http://www.securityfocus.com/bid/74765
DSA-3266
http://www.debian.org/security/2015/dsa-3266
DSA-3268
http://www.debian.org/security/2015/dsa-3268
FEDORA-2015-8751
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159831.html
FEDORA-2015-8756
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159683.html
FEDORA-2015-8771
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159543.html
FEDORA-2015-8773
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159298.html
FEDORA-2015-8777
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160106.html
FEDORA-2015-8782
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160094.html
GLSA-201603-04
https://security.gentoo.org/glsa/201603-04
GLSA-201701-19
https://security.gentoo.org/glsa/201701-19
USN-2617-1
http://www.ubuntu.com/usn/USN-2617-1
USN-2617-2
http://www.ubuntu.com/usn/USN-2617-2
USN-2617-3
http://www.ubuntu.com/usn/USN-2617-3
[oss-security] 20150521 CVE-2015-3202 fuse privilege escalation
http://www.openwall.com/lists/oss-security/2015/05/21/9
http://packetstormsecurity.com/files/132021/Fuse-Local-Privilege-Escalation.html
https://gist.github.com/taviso/ecb70eb12d461dd85cba
https://twitter.com/taviso/status/601370527437967360
openSUSE-SU-2015:0997
http://lists.opensuse.org/opensuse-updates/2015-06/msg00005.html
openSUSE-SU-2015:1003
http://lists.opensuse.org/opensuse-updates/2015-06/msg00007.html
CopyrightCopyright (C) 2015 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.