DSA-4257 fuse – security update

Jann Horn discovered that FUSE, a Filesystem in USErspace, allows thebypass of the user_allow_other restriction when SELinux is active(including in permissive mode). A local user can take advantage of thisflaw in the fusermount utility to bypass the system configuration andmount a FUSE filesystem with the allow_other mount option. More info: https://www.debian.org/security/2018/dsa-4257
Translate »