Menu

#1 Patch: CVE-2008-2232: privilege escalation

open
nobody
None
9
2008-08-20
2008-08-20
No

afuse is vulnerable to a local privilege escalation because the expand_template function passes metacharacters from the pathname unescaped to the shell. This issue is tracked as CVE-2008-2232:
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2232

I submitted a patch to the Debian security team, and they released fixed packages:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490921
However, the vulnerability is still present in your current release and Subversion trunk.

The patch is available from the above Debian bug report, and I have also attached it here.

Discussion

  • Anders Kaseorg

    Anders Kaseorg - 2008-08-20
     
  • Anders Kaseorg

    Anders Kaseorg - 2008-08-20
    • priority: 5 --> 9
     

Log in to post a comment.

MongoDB Logo MongoDB