First published: Fri Jun 03 2005(Updated: )
FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fuse | =2.2 | |
Fuse | =2.3_rc1 | |
Fuse | =2.2.1 | |
Fuse | =2.3_pre |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1858 has been classified as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2005-1858, upgrade your FUSE installation to version 2.3.0 or later.
CVE-2005-1858 affects FUSE versions 2.2, 2.2.1, 2.3_rc1, and 2.3_pre.
CVE-2005-1858 is a local vulnerability, meaning it requires local access to the system to be exploited.
CVE-2005-1858 may allow local users to read previously used memory, potentially revealing sensitive data.