Bug 112902 - sys-fs/fuse: fusermount can corrupt /etc/mtab (CVE-2005-3531)
Bug#: 112902 Product:  Gentoo Security Version: unspecified Platform: All
OS/Version: Linux Status: RESOLVED Severity: normal Priority: P2
Resolution: FIXED Assigned To: security@gentoo.org Reported By: koon@gentoo.org
Component: Vulnerabilities
URL:  http://cvs.sourceforge.net/viewcvs.py/fuse/fuse/util/fusermount.c?r1=1.69&r2=1.70
Summary: sys-fs/fuse: fusermount can corrupt /etc/mtab (CVE-2005-3531)
Keywords:  
Status Whiteboard: B2? [glsa] koon
Opened: 2005-11-18 04:55 0000
Description:   Opened: 2005-11-18 04:55 0000
Thomas Biege discovered that fusermount can be abused to corrupt the /etc/mtab.
He thinks it can be used to set mount options for the fuse FS. This only works
if fusermount is setuid root (default on Gentoo) :

-rwsr-xr-x  1 root root 18820 Nov 18 13:47 fusermount

Miklos Szeredi <miklos@szeredi.hu> is preparing a patch, waiting for the
disclosure date.

------- Comment #1 From Thierry Carrez (RETIRED) 2005-11-19 03:32:17 0000 -------
Created an attachment (id=73173) [details]
fusermount.patch

Patch from Miklos.

------- Comment #2 From Thierry Carrez (RETIRED) 2005-11-19 03:33:43 0000 -------
Ccing maintainer. 
genstef: please prepare a new ebuild but do not commit anything to Portage yet.
We are waiting for an embargo end date.

------- Comment #3 From Sune Kloppenborg Jeppesen 2005-11-19 13:17:49 0000 -------
Fix committed to upstream CVS. Please provide and commit an updated ebuild. 

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-11-19 14:20:11 0000 -------
genstef, just note the bug # in the Changelog for now and nothing else.  

------- Comment #5 From Stefan Schweizer 2005-11-19 15:24:26 0000 -------
I committed an updated ebuild, 2.4.1-r1

I hope it is ok, that I revbumped it

------- Comment #6 From Sune Kloppenborg Jeppesen 2005-11-19 23:49:01 0000 -------
Thx Stefan. 
 
Arch security liaisons, please test and mark stable. Don't do any verbose  
Changelogs at this time, it's still not completely public. 
  
Calling:  
ppc -> hansmi  
amd64 -> blubb  
x86 -> halcy0n  

------- Comment #7 From Michael Hanselmann (hansmi) (RETIRED) 2005-11-20 02:21:38 0000 -------
Marked stable on ppc.

------- Comment #8 From Simon Stelling (RETIRED) 2005-11-20 11:03:05 0000 -------
sir, amd64 stable, sir.

------- Comment #9 From Mark Loeser 2005-11-20 11:30:46 0000 -------
x86 done

------- Comment #10 From Sune Kloppenborg Jeppesen 2005-11-20 13:02:07 0000 -------
Waiting for public disclsure. 

------- Comment #11 From Thierry Carrez (RETIRED) 2005-11-22 08:58:27 0000 -------
GLSA 200511-17