CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:M/Au:N/C:N/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
10.1%
fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.
Vendor | Product | Version | CPE |
---|---|---|---|
fuse | fuse | 1.9 | cpe:2.3:a:fuse:fuse:1.9:*:*:*:*:*:*:* |
fuse | fuse | 2.0 | cpe:2.3:a:fuse:fuse:2.0:pre0:*:*:*:*:*:* |
fuse | fuse | 2.0 | cpe:2.3:a:fuse:fuse:2.0:pre1:*:*:*:*:*:* |
fuse | fuse | 2.1 | cpe:2.3:a:fuse:fuse:2.1:*:*:*:*:*:*:* |
fuse | fuse | 2.2 | cpe:2.3:a:fuse:fuse:2.2:*:*:*:*:*:*:* |
fuse | fuse | 2.2.1 | cpe:2.3:a:fuse:fuse:2.2.1:*:*:*:*:*:*:* |
fuse | fuse | 2.3 | cpe:2.3:a:fuse:fuse:2.3:pre:*:*:*:*:*:* |
fuse | fuse | 2.3 | cpe:2.3:a:fuse:fuse:2.3:rc1:*:*:*:*:*:* |
fuse | fuse | 2.3.0 | cpe:2.3:a:fuse:fuse:2.3.0:*:*:*:*:*:*:* |
fuse | fuse | 2.4.0 | cpe:2.3:a:fuse:fuse:2.4.0:*:*:*:*:*:*:* |
bugs.debian.org/cgi-bin/bugreport.cgi?bug=567633
lists.fedoraproject.org/pipermail/package-announce/2010-February/034518.html
lists.fedoraproject.org/pipermail/package-announce/2010-February/034580.html
lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html
lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html
lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
secunia.com/advisories/38261
secunia.com/advisories/38287
secunia.com/advisories/38359
secunia.com/advisories/38437
sourceforge.net/projects/fuse/files/fuse-2.X/2.7.5/fuse-2.7.5.tar.gz/download
sourceforge.net/projects/fuse/files/ReleaseNotes/fuse-2.8.3.html/view
www.debian.org/security/2010/dsa-1989
www.securityfocus.com/bid/37983
www.ubuntu.com/usn/USN-892-1
www.vupen.com/english/advisories/2010/1107
bugzilla.redhat.com/show_bug.cgi?id=532940
bugzilla.redhat.com/show_bug.cgi?id=558833
exchange.xforce.ibmcloud.com/vulnerabilities/55945