CVE-2016-1233 Information

Description

An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2 in stretch before 2.9.5-1 and in sid before 2.9.5-1 sets world-writable permissions for the /dev/cuse character device which allows local users to gain privileges via a character device in /dev related to an ioctl.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

http://www.debian.org/security/2016/dsa-3451

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.8

Share on: