PT-2015-6093 · Filesystem In Userspace+2 · Fuse+2

Tavis Ormandy

·

Publicado

2015-05-20

·

Atualizado

2024-06-15

·

CVE-2015-3202

CVSS v2.0

3.6

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions FUSE versions prior to 2.9.3-15
Description The issue arises from fusermount in FUSE not properly clearing the environment before invoking mount or umount as root. This allows local users to write to arbitrary files via a crafted LIBMOUNT MTAB environment variable that is used by mount's debugging feature.
Recommendations For versions prior to 2.9.3-15, update to version 2.9.3-15 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-3202
DLA-226-1
DLA-226-2
DLA-238-1
DSA-3266-1
DSA-3268-1
DSA-3268-2
MGASA-2015-0239
OPENSUSE-SU-2024:10378-1
SUSE-SU-2015:1024-1
SUSE-SU-2015:1053-1
SUSE-SU-2015_1024-1
SUSE-SU-2015_1053-1
USN-2617-1
USN-2617-2
USN-2617-3

Produtos afetados

Fuse
Suse
Ubuntu