Vulnerability Description
An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in sid before 2.9.5-1 sets world-writable permissions for the /dev/cuse character device, which allows local users to gain privileges via a character device in /dev, related to an ioctl.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Fuse | <= 2.9.3-14 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://www.debian.org/security/2016/dsa-3451Vendor Advisory
- http://www.debian.org/security/2016/dsa-3451Vendor Advisory
FAQ
What is CVE-2016-1233?
CVE-2016-1233 is a vulnerability with a CVSS score of 7.8 (HIGH). An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in sid before 2.9.5-1 sets world-writable permissions for the /dev/cuse character d...
How severe is CVE-2016-1233?
CVE-2016-1233 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1233?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Fuse, Debian Debian Linux.