CVE-2005-1858: Low severity fuse FUSE vulnerability
Published Jun 3, 2005
·Updated
FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.
Affected Software
4 affected components
fuse FUSE=2.2
fuse FUSE=2.3_rc1
fuse FUSE=2.2.1
fuse FUSE=2.3_pre
Remediation
Patch Available
Event History
Jun 3, 2005
CVE Published
04:00 AM
Jun 6, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1858?
CVE-2005-1858 has been classified as a medium severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2005-1858?
To fix CVE-2005-1858, upgrade your FUSE installation to version 2.3.0 or later.
3
What software is affected by CVE-2005-1858?
CVE-2005-1858 affects FUSE versions 2.2, 2.2.1, 2.3_rc1, and 2.3_pre.
4
Can CVE-2005-1858 be exploited remotely?
CVE-2005-1858 is a local vulnerability, meaning it requires local access to the system to be exploited.
5
What kind of information can be leaked due to CVE-2005-1858?
CVE-2005-1858 may allow local users to read previously used memory, potentially revealing sensitive data.