Go to file
Tudor Florea 7f1df52e94 fuse: fix for CVE-2015-3202 Privilege Escalation
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before
invoking (1) mount or (2) umount as root, which allows local users to write
to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is
used by mount's debugging feature.

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3202
http://www.openwall.com/lists/oss-security/2015/05/21/9

Signed-off-by: Tudor Florea <tudor.florea@enea.com>
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-07-19 17:05:16 -07:00
contrib contrib/tesseract-langs.sh: add script to generate recipes for tesseract languages 2014-06-10 12:16:23 +02:00
meta-efl meta-efl: Add LAYERVERSION and LAYERDEPENDS 2015-01-28 08:59:25 +01:00
meta-filesystems fuse: fix for CVE-2015-3202 Privilege Escalation 2015-07-19 17:05:16 -07:00
meta-gnome libsecret: add missing dependency on intltool-native 2015-04-29 19:24:09 +02:00
meta-gpe meta-gpe: Add LAYERVERSION and LAYERDEPENDS 2015-01-28 08:59:26 +01:00
meta-initramfs update maintainer info in README's for dizzy 2014-10-30 09:07:58 +01:00
meta-multimedia PNBLACKLIST: use weak assignments 2014-12-26 18:04:33 -08:00
meta-networking ipsec-tools: Security Advisory - CVE-2015-4047 2015-07-19 16:42:14 -07:00
meta-oe mariadb: Security Advisory -CVE-2015-2305 2015-07-19 16:15:08 -07:00
meta-perl meta-perl: Add LAYERVERSION and LAYERDEPENDS 2015-01-28 08:59:25 +01:00
meta-python python-pip: add python-distribute in RDEPENDS 2015-03-21 07:56:31 -07:00
meta-ruby meta-ruby: Add LAYERVERSION and LAYERDEPENDS 2015-01-28 08:59:25 +01:00
meta-systemd update maintainer info in README's for dizzy 2014-10-30 09:07:58 +01:00
meta-webserver PNBLACKLIST: use weak assignments 2014-12-26 18:04:33 -08:00
meta-xfce xfce4-diskperf-plugin: Specify BSD license 2015-03-21 07:53:03 -07:00
toolchain-layer toolchain-layer: Add LAYERVERSION and LAYERDEPENDS 2015-01-28 08:59:25 +01:00
.gitignore gitignore: Ignore Edit backup files, patches, .rej, .orig, .swp 2013-11-24 15:19:27 +01:00
COPYING.MIT add README and license for this layer 2011-02-13 16:47:32 +01:00
README README: add top level readme, update meta-oe one 2011-10-17 09:27:01 +02:00

Collection of layers for the OE-core universe

Please see the respective READMEs in the layer subdirectories