Go to file
Tudor Florea 6a591c9367 fuse: fix for CVE-2015-3202 Privilege Escalation
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before
invoking (1) mount or (2) umount as root, which allows local users to write
to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is
used by mount's debugging feature.

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3202
http://www.openwall.com/lists/oss-security/2015/05/21/9

Signed-off-by: Tudor Florea <tudor.florea@enea.com>
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-10-26 21:43:08 +01:00
contrib contrib/tesseract-langs.sh: add script to generate recipes for tesseract languages 2014-06-10 12:16:23 +02:00
meta-efl fido README: update maintainers list 2015-04-13 13:10:53 +02:00
meta-filesystems fuse: fix for CVE-2015-3202 Privilege Escalation 2015-10-26 21:43:08 +01:00
meta-gnome gdm: Whitelist it 2015-08-03 09:06:58 -07:00
meta-gpe fido README: update maintainers list 2015-04-13 13:10:53 +02:00
meta-initramfs fido README: update maintainers list 2015-04-13 13:10:53 +02:00
meta-multimedia gupnp-igd: fix missing dependencies 2015-10-13 13:48:19 +02:00
meta-networking ipsec-tools: Security Advisory - CVE-2015-4047 2015-10-26 21:43:08 +01:00
meta-oe mariadb: Security Advisory -CVE-2015-2305 2015-10-26 21:43:08 +01:00
meta-perl fido README: update maintainers list 2015-04-13 13:10:53 +02:00
meta-python python-pyzmq: Add python-multiprocessing in RDEPENDS 2015-09-18 14:07:50 +02:00
meta-ruby ruby: explicitly disable dtrace support 2015-10-14 21:17:27 +02:00
meta-systemd dhcp: fix parsing warning 2015-09-15 16:06:58 +02:00
meta-webserver fido README: update maintainers list 2015-04-13 13:10:53 +02:00
meta-xfce fido README: update maintainers list 2015-04-13 13:10:53 +02:00
toolchain-layer fido README: update maintainers list 2015-04-13 13:10:53 +02:00
.gitignore gitignore: Ignore Edit backup files, patches, .rej, .orig, .swp 2013-11-24 15:19:27 +01:00
COPYING.MIT add README and license for this layer 2011-02-13 16:47:32 +01:00
README README: add top level readme, update meta-oe one 2011-10-17 09:27:01 +02:00

Collection of layers for the OE-core universe

Please see the respective READMEs in the layer subdirectories