Fixes CVE-2008-2232: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2232. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-8816 2009-08-20 20:34:04 -------------------------------------------------------------------------------- Name : afuse Product : Fedora 11 Version : 0.2 Release : 4.fc11 URL : Summary : An automounter implemented with FUSE Description : Afuse is an automounting file system implemented in user-space using FUSE. Afuse currently implements the most basic functionality that can be expected by an automounter; that is it manages a directory of virtual directories. If one of these virtual directories is accessed and is not already automounted, afuse will attempt to mount a filesystem onto that directory. If the mount succeeds the requested access proceeds as normal, otherwise it will fail with an error. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2008-2232: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2232 -------------------------------------------------------------------------------- ChangeLog: * Mon Aug 17 2009 Tom "spot" Callaway - 0.2-4 - fix CVS-2008-2232 * Fri Jul 24 2009 Fedora Release Engineering - 0.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update afuse' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailinglist
Fixes CVE-2008-2232: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2232. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-8792 2009-08-20 20:33:40 -------------------------------------------------------------------------------- Name : afuse Product : Fedora 10 Version : 0.2 Release : 4.fc10 URL : Summary : An automounter implemented with FUSE Description : Afuse is an automounting file system implemented in user-space using FUSE. Afuse currently implements the most basic functionality that can be expected by an automounter; that is it manages a directory of virtual directories. If one of these virtual directories is accessed and is not already automounted, afuse will attempt to mount a filesystem onto that directory. If the mount succeeds the requested access proceeds as normal, otherwise it will fail with an error. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2008-2232: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2232 -------------------------------------------------------------------------------- ChangeLog: -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update afuse' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Anders Kaseorg discovered that afuse, an automounting file system in user-space, did not properly escape meta characters in paths. This allowed a local attacker with read access to the filesystem to execute commands as the owner of the filesystem.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1611-1
Get the latest Linux and open source security news straight to your inbox.