bugs.debian.orgConfirmation
http://bugs.debian.org/311634 CVE-2005-1858
FUSE 2.2/2.3 - Local Information Disclosure
Record summary
CVE-2005-1858 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFUSE 2.2/2.3 - Local Information DisclosureExploitDB exploitby Miklos SzerediNot analyzed1 file
References
1015561Third-party advisory
http://secunia.com/advisories/15561 16024Third-party advisory
http://secunia.com/advisories/16024 1014107vdb entry
http://securitytracker.com/id?1014107 sourceforge.netConfirmation
http://sourceforge.net/project/shownotes.php?release_id=331884 DSA-744Vendor advisory
http://www.debian.org/security/2005/dsa-744 17042vdb entry
http://www.osvdb.org/17042 13857vdb entry
http://www.securityfocus.com/bid/13857 sven-tantau.de
http://www.sven-tantau.de/public_files/fuse/fuse_20050603.txt nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-1858