[Full-disclosure] fusermount: Unmount any filesystem

halfdog me at halfdog.net
Tue Nov 2 17:44:11 GMT 2010


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello List,

To evaluate the pros and cons of various disclosure methods, I'm trying
full disclosure this time:

At least on ubuntu lucid, the fusermount tool contains a timerace
mounting a user filesystem and updating mtab, thus mtab entries with
arbitrary path can be created. Crafted mtab entries can then be used to
unmount live parts of the filesystem.

http://www.halfdog.net/Security/FuseTimerace/

- -- 
http://www.halfdog.net/
PGP: 156A AE98 B91F 0114 FE88  2BD8 C459 9386 feed a bee
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFM0E3rxFmThv7tq+4RAmavAJ9JNdwF6R0gv1FlIZ3to1QrkQs90wCgkUvA
IpD9Wfe/viLLIMLEfE1B2yo=
=tFrk
-----END PGP SIGNATURE-----



Full-Disclosure is hosted and sponsored by Secunia.