3.3
CVSSv2

CVE-2011-0543

Published: 02/09/2011 Updated: 13/02/2023
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Certain legacy functionality in fusermount in fuse 2.8.5 and previous versions, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

fuse fuse 2.4.2

fuse fuse 2.6.0

fuse fuse 2.4.1

fuse fuse 2.2

fuse fuse 2.6.5

fuse fuse 2.7.0

fuse fuse 2.7.4

fuse fuse 2.3.0

fuse fuse 2.4.0

fuse fuse 2.6.3

fuse fuse 2.5.3

fuse fuse 2.3

fuse fuse 2.0

fuse fuse 2.8.1

fuse fuse 2.2.1

fuse fuse 2.5.1

fuse fuse 2.7.1

fuse fuse 2.8.2

fuse fuse 2.7.2

fuse fuse 2.1

fuse fuse 2.8.0

fuse fuse 2.5.2

fuse fuse

fuse fuse 1.9

fuse fuse 2.7.5

fuse fuse 2.7.6

fuse fuse 2.5.0

fuse fuse 2.6.1

fuse fuse 2.8.4

fuse fuse 2.8.3

fuse fuse 2.7.3

Vendor Advisories

Debian Bug report logs - #624551 Three more security issues: CVE-2011-0541, CVE-2011-0542, CVE-2011-0543 Package: fuse; Maintainer for fuse is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Source for fuse is src:fuse (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Fri, 29 Apr 2011 ...
It was discovered that FUSE would incorrectly follow symlinks when checking mountpoints under certain conditions A local attacker, with access to use FUSE, could unmount arbitrary locations, leading to a denial of service ...