PT-2005-1094 · Filesystem In Userspace · Fuse
Thomas Biege
·
Published
2005-11-22
·
Updated
2011-03-08
·
CVE-2005-3531
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FUSE versions prior to 2.4.1
Description
The issue allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters. This can lead to a violation of protected information integrity. The exploitation of this issue can be carried out locally.
Recommendations
For versions prior to 2.4.1, update to version 2.4.1 or later to resolve the issue. As a temporary workaround, consider removing the setuid root bit from fusermount to prevent local users from exploiting this issue. Restrict access to fusermount to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fuse