[ubuntu/natty] fuse 2.8.4-1.1ubuntu4 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Thu Feb 10 21:00:29 UTC 2011


fuse (2.8.4-1.1ubuntu4) natty; urgency=low

  * SECURITY UPDATE: arbitrary unprivileges unmount
    - debian/patches/005-CVE-2011-0541.patch: don't follow symlinks when
      unmounting in case of a failed mtab update in util/fusermount.c.
    - debian/patches/006-CVE-2011-0542.patch: chdir to / before performing
      mount/umount in util/fusermount.c.
    - debian/patches/007-CVE-2011-0543.patch: remove legacy util-linux
      support so symlinks don't get followed upon fallback in
      lib/mount_util.c, util/fusermount.c. Remove unneeded
      --disable-legacy-umount option in configure.in.
    - debian/rules: remove dh_autoreconf and obsolete
      --disable-legacy-umount configure option.
    - debian/control: Remove dh-autoreconf from Build-Depends.
    - CVE-2011-0541
    - CVE-2011-0542
    - CVE-2011-0543
  * Removed unused 003-CVE-2009-3297.dpatch patch.

Date: Thu, 10 Feb 2011 14:55:36 -0500
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/natty/+source/fuse/2.8.4-1.1ubuntu4
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 10 Feb 2011 14:55:36 -0500
Source: fuse
Binary: fuse-utils libfuse-dev libfuse2 fuse-utils-udeb libfuse2-udeb
Architecture: source
Version: 2.8.4-1.1ubuntu4
Distribution: natty
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 fuse-utils - Filesystem in USErspace (utilities)
 fuse-utils-udeb - Filesystem in USErspace (utilities) (udeb)
 libfuse-dev - Filesystem in USErspace (development files)
 libfuse2   - Filesystem in USErspace library
 libfuse2-udeb - Filesystem in USErspace library (udeb)
Changes: 
 fuse (2.8.4-1.1ubuntu4) natty; urgency=low
 .
   * SECURITY UPDATE: arbitrary unprivileges unmount
     - debian/patches/005-CVE-2011-0541.patch: don't follow symlinks when
       unmounting in case of a failed mtab update in util/fusermount.c.
     - debian/patches/006-CVE-2011-0542.patch: chdir to / before performing
       mount/umount in util/fusermount.c.
     - debian/patches/007-CVE-2011-0543.patch: remove legacy util-linux
       support so symlinks don't get followed upon fallback in
       lib/mount_util.c, util/fusermount.c. Remove unneeded
       --disable-legacy-umount option in configure.in.
     - debian/rules: remove dh_autoreconf and obsolete
       --disable-legacy-umount configure option.
     - debian/control: Remove dh-autoreconf from Build-Depends.
     - CVE-2011-0541
     - CVE-2011-0542
     - CVE-2011-0543
   * Removed unused 003-CVE-2009-3297.dpatch patch.
Checksums-Sha1: 
 43f123dc73a3bc1c50d533234e52a3a7ca7eeb52 1988 fuse_2.8.4-1.1ubuntu4.dsc
 93f092c86f6ae4a8527efc585433a703a061f927 27350 fuse_2.8.4-1.1ubuntu4.diff.gz
Checksums-Sha256: 
 cbebbd10485789b258bb221dee31a2a8db68541cd99fcc59c80b8ad1a7206c71 1988 fuse_2.8.4-1.1ubuntu4.dsc
 f7de56cdb75fc0151ac68cc93dd7ae44d4b4f54c679df2b679ad3f6fe0a9b84d 27350 fuse_2.8.4-1.1ubuntu4.diff.gz
Files: 
 850443f18a284932bb452ecf1ce5b3d7 1988 libs optional fuse_2.8.4-1.1ubuntu4.dsc
 a65a01f3ef7a223712f014c975aed669 27350 libs optional fuse_2.8.4-1.1ubuntu4.diff.gz
Original-Maintainer: Bartosz Fenski <fenio at debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQIcBAEBCgAGBQJNVE/qAAoJEGVp2FWnRL6T5lYQAIZN2njPDCb406sv/TRKb4kz
1LOanPcmiXNl7Byz3eTvynTSgNmNGdEbhzg6pYL0aLbEd0jQfn14XK/tObOK7fHa
m5KLiIDQ9D/kyIg4vQIXhsuRsDnrTm2am+FV7LsYNRsbk+YI4XAnoIcXNOvC0b3g
+nT0c1fu8b2BWRbZyPNYHVcWSFRhAiE522TY5JGKMheUvuz7EJabG+9VtQCVpUAV
N0e6XIthi1RL6zJoiTWCBoHzDpUXup0iB5cUsfOQRLk1EGlT/EjlVTWLFkmMpbE0
r41UaOgXbR7DVn2MDHh3PxZix/BWIvCH3b5G/ixuUzHTnvRx9C9H8ZFAb4nTEHz+
DfbkqStIJ65JcUv3YITyoNCoB7zts8kENAdFv8+5ySWLi2W//Pv1CaqWWuWeVI75
3mfGtAkk6QUSYgB4f9Xrs/fX+rKUm34+dtsRgCSsYnuXvlnGPwP+lFlOLQeRTlir
pqeHggWaUBYKZ42IeaQ2C6izjiuut1g83q7c6fOCR9TIKKN4S3ND3wFpUq9AT19Z
BiBpQgSYuOJvkHtsYusv48PHx/SGWSZLfNzh7d/MWq2sGCqsO0sTqmh9uOSdhZUo
swCbGZqe1YOZlien2wgOoFmHD0wu1DmxazKpObrnDLCN2Zf8aPg0xr34s/2NZE8J
FpzryzP9ZVtVtlAn46gt
=wX5I
-----END PGP SIGNATURE-----


More information about the Natty-changes mailing list