[ubuntu/lucid] fuse 2.8.1-1.1ubuntu2 (Accepted)

Kees Cook kees at ubuntu.com
Wed Jan 27 00:25:17 GMT 2010


fuse (2.8.1-1.1ubuntu2) lucid; urgency=low

  * SECURITY UPDATE: local attacker can trick fuse into unmounting a
    filesystem from the wrong location.
    - debian/patches/200-fix_mount_symlink_handling: upstream
      fixes.
    - CVE-2009-3297

Date: Mon, 25 Jan 2010 17:10:52 -0800
Changed-By: Kees Cook <kees at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/lucid/+source/fuse/2.8.1-1.1ubuntu2
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Mon, 25 Jan 2010 17:10:52 -0800
Source: fuse
Binary: fuse-utils libfuse-dev libfuse2 fuse-utils-udeb libfuse2-udeb
Architecture: source
Version: 2.8.1-1.1ubuntu2
Distribution: lucid
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Kees Cook <kees at ubuntu.com>
Description: 
 fuse-utils - Filesystem in USErspace (utilities)
 fuse-utils-udeb - Filesystem in USErspace (utilities) (udeb)
 libfuse-dev - Filesystem in USErspace (development files)
 libfuse2   - Filesystem in USErspace library
 libfuse2-udeb - Filesystem in USErspace library (udeb)
Changes: 
 fuse (2.8.1-1.1ubuntu2) lucid; urgency=low
 .
   * SECURITY UPDATE: local attacker can trick fuse into unmounting a
     filesystem from the wrong location.
     - debian/patches/200-fix_mount_symlink_handling: upstream
       fixes.
     - CVE-2009-3297
Checksums-Sha1: 
 195c98d0c481ac9bca14b13360bde0065f5b50a1 1386 fuse_2.8.1-1.1ubuntu2.dsc
 3376fe0fec2955bff0fb5ec6286a67a9b8ba0148 23770 fuse_2.8.1-1.1ubuntu2.diff.gz
Checksums-Sha256: 
 bd8dbd0802e6426c22da14947092116bc8a0559c93b64059ce88c370e2a7894e 1386 fuse_2.8.1-1.1ubuntu2.dsc
 d3f4aa5a2c088a1f539e1018031a183be890c1711f24f538563396b780b3d94f 23770 fuse_2.8.1-1.1ubuntu2.diff.gz
Files: 
 543f8be69c4deb7bd058cb46b2ccc443 1386 libs optional fuse_2.8.1-1.1ubuntu2.dsc
 5fa453e79cd3cc17befc9959483b73e9 23770 libs optional fuse_2.8.1-1.1ubuntu2.diff.gz
Original-Maintainer: Bartosz Fenski <fenio at debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Kees Cook <kees at outflux.net>

iEYEARECAAYFAktfhjgACgkQH/9LqRcGPm1QNQCdERi+vIgn7vdw+CMwK7bNS+W6
HkgAniaz243FoRlhmmKgQRlDrolhO709
=d7J8
-----END PGP SIGNATURE-----


More information about the Lucid-changes mailing list