CVE-2015-3202
ntfs-3g - security update
EPSS 1.0%
描述
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
如何修補 CVE-2015-3202
要修補 CVE-2015-3202,請將受影響套件升級到下列已修補版本。
- Debian/fuse—升級至 2.9.3-16 或更新版本
- Debian/fuse—升級至 2.8.4-1.1+deb6u1 或更新版本
- Debian/fuse—升級至 2.9.0-2+deb7u2 或更新版本
- —升級至 1:2014.2.15AR.3-3 或更新版本
- —升級至 1:2010.3.6-1+deb6u1 或更新版本
- —升級至 1:2010.3.6-1+deb6u2 或更新版本
- —升級至 1:2012.1.15AR.5-2.1+deb7u1 或更新版本
- —升級至 1:2012.1.15AR.5-2.1+deb7u2 或更新版本
CVE-2015-3202 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(8)
- from 0, < 2.9.3-16
- from 0, < 2.8.4-1.1+deb6u1
- from 0, < 2.9.0-2+deb7u2
- from 0, < 1:2014.2.15AR.3-3
- from 0, < 1:2010.3.6-1+deb6u1
- from 0, < 1:2010.3.6-1+deb6u2
- from 0, < 1:2012.1.15AR.5-2.1+deb7u1
- from 0, < 1:2012.1.15AR.5-2.1+deb7u2