Yesterday a local root exploit for fuse was published. The updates are all deployed by now, but this deserves a more structured followup:
The only reason fuse is installed on almost 1000 servers is because ntfs-3g depends on it. ntfs-3g in turn is only installed because it is a Recommends: of ubuntu-standard (and since we install all Recommends by default, it gets installed everywhere.
I plan to
- get rid of ntfs-3g/fuse on existing servers (after checking with individual "service owners" whether they might have an exotic use case for NTFS partitions, I cannot imagine one, though)
- patch ubuntu-standard for trusty-wikimedia and precise-wikimedia to drop the Recommends:
- review whether there are similar security-sensitive packages which are likely unneeded, but get pulled in via unexpected Depends/Recommends