Lucene search

K
cve[email protected]CVE-2010-3879
HistoryJan 22, 2011 - 10:00 p.m.

CVE-2010-3879

2011-01-2222:00:02
CWE-59
web.nvd.nist.gov
29
cve-2010-3879
fuse
symlink attack
mtab entries
arbitrary pathnames
filesystem
vulnerability

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

6.1 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

29.4%

FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.

Affected configurations

NVD
Node
libfuse_projectlibfuseRange2.8.5

References

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

6.1 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

29.4%