5.8
CVSSv2

CVE-2010-3879

Published: 22/01/2011 Updated: 10/11/2020
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

FUSE, possibly 2.8.5 and previous versions, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.

Vulnerable Product Search on Vulmon Subscribe to Product

libfuse project libfuse

Vendor Advisories

Debian Bug report logs - #602333 /usr/bin/fusermount: fusermount allows unmount any filesystem Package: fuse-utils; Maintainer for fuse-utils is (unknown); Reported by: Paul Szabo <paulszabo@sydneyeduau> Date: Wed, 3 Nov 2010 20:27:01 UTC Severity: grave Tags: security, squeeze-ignore Found in versions fuse/284-11, ...
It was discovered that FUSE could be tricked into incorrectly updating the mtab file when mounting filesystems A local attacker, with access to use FUSE, could unmount arbitrary locations, leading to a denial of service ...
USN-1045-1 fixed vulnerabilities in FUSE This update to util-linux adds support for new options required by the FUSE update ...

Exploits

source: wwwsecurityfocuscom/bid/44623/info wwwhalfdognet/Security/FuseTimerace/ FUSE fusermount tool is prone to a race-condition vulnerability A local attacker can exploit this issue to cause a denial of service by unmounting any filesystem of the system githubcom/offensive-security/exploitdb-bin-splo ...