PT-2010-2520 · Filesystem In Userspace · Fuse

Dan Rosenberg

·

Published

2010-03-02

·

Updated

2017-08-17

·

CVE-2010-0789

CVSS v2.0

3.3

Low

VectorAV:L/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions FUSE versions prior to 2.7.5 FUSE versions 2.8.x prior to 2.8.2
Description The issue allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint. This is related to the fusermount component in FUSE.
Recommendations For FUSE versions prior to 2.7.5, update to version 2.7.5 or later. For FUSE versions 2.8.x prior to 2.8.2, update to version 2.8.2 or later.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0789
DSA-1989-1

Affected Products

Fuse