3.3
CVSSv2

CVE-2010-0789

Published: 02/03/2010 Updated: 17/08/2017
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

fusermount in FUSE prior to 2.7.5, and 2.8.x prior to 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.

Vulnerable Product Search on Vulmon Subscribe to Product

fuse fuse 2.4.1

fuse fuse 2.4.2

fuse fuse 2.6.3

fuse fuse 2.6.5

fuse fuse 2.7.0

fuse fuse 2.3

fuse fuse 2.3.0

fuse fuse 2.4.0

fuse fuse 2.6.0

fuse fuse 2.6.1

fuse fuse 2.2

fuse fuse 2.2.1

fuse fuse 1.9

fuse fuse 2.0

fuse fuse 2.5.0

fuse fuse 2.5.1

fuse fuse 2.7.1

fuse fuse 2.7.2

fuse fuse 2.1

fuse fuse 2.5.2

fuse fuse 2.5.3

fuse fuse 2.7.3

fuse fuse 2.7.4

Vendor Advisories

Debian Bug report logs - #602333 /usr/bin/fusermount: fusermount allows unmount any filesystem Package: fuse-utils; Maintainer for fuse-utils is (unknown); Reported by: Paul Szabo <paulszabo@sydneyeduau> Date: Wed, 3 Nov 2010 20:27:01 UTC Severity: grave Tags: security, squeeze-ignore Found in versions fuse/284-11, ...
Dan Rosenberg discovered that FUSE did not correctly check mount locations A local attacker, with access to use FUSE, could unmount arbitrary locations, leading to a denial of service ...