PT-2005-1094 · Filesystem In Userspace · Fuse

Thomas Biege

·

Published

2005-11-22

·

Updated

2011-03-08

·

CVE-2005-3531

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FUSE versions prior to 2.4.1
Description The issue allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters. This can lead to a violation of protected information integrity. The exploitation of this issue can be carried out locally.
Recommendations For versions prior to 2.4.1, update to version 2.4.1 or later to resolve the issue. As a temporary workaround, consider removing the setuid root bit from fusermount to prevent local users from exploiting this issue. Restrict access to fusermount to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09487
CVE-2005-3531
DTSA-27-1

Affected Products

Fuse