Bug#904439: fuse: CVE-2018-10906: Restriction bypass of the "allow_other" option when SELinux is active

2018-07-24 Thread Salvatore Bonaccorso
On Tue, Jul 24, 2018 at 01:12:50PM +0200, Salvatore Bonaccorso wrote: > I have prepared an update for stretch (not yet released), although as > said, its a problem only with active SELinux, which is not by default > in Debian. Attaching debdiff. Regards, Salvatore diff -Nru

Bug#904439: fuse: CVE-2018-10906: Restriction bypass of the "allow_other" option when SELinux is active

2018-07-24 Thread Salvatore Bonaccorso
Source: fuse Version: 2.9.7-1 Severity: important Tags: patch security upstream Forwarded: https://github.com/libfuse/libfuse/pull/268 Hi, The following vulnerability was published for fuse. CVE-2018-10906[0]: Restriction bypass of the "allow_other" option when SELinux is active To exploit it,