CVE-2016-1233: High severity debian fuse vulnerability
An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in sid before 2.9.5-1 sets world-writable permissions for the /dev/cuse character device, which allows local users to gain privileges via a character device in /dev, related to an ioctl.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1233?
CVE-2016-1233 has a medium severity rating due to its potential for local privilege escalation.
How do I fix CVE-2016-1233?
To fix CVE-2016-1233, upgrade the affected Debian fuse package to version 2.9.3-15+deb8u2 or later.
Which versions are affected by CVE-2016-1233?
CVE-2016-1233 affects Debian fuse versions below 2.9.3-15+deb8u2.
Can local users exploit CVE-2016-1233?
Yes, local users can exploit CVE-2016-1233 to gain elevated privileges through the insecure /dev/cuse character device.
Is there a workaround for CVE-2016-1233?
A temporary workaround for CVE-2016-1233 is to manually change the permissions of the /dev/cuse device to restrict access.