PT-2015-6093 · Filesystem In Userspace+2 · Fuse+2

Tavis Ormandy

·

Published

2015-05-20

·

Updated

2024-06-15

·

CVE-2015-3202

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions FUSE versions prior to 2.9.3-15
Description The issue arises from fusermount in FUSE not properly clearing the environment before invoking mount or umount as root. This allows local users to write to arbitrary files via a crafted LIBMOUNT MTAB environment variable that is used by mount's debugging feature.
Recommendations For versions prior to 2.9.3-15, update to version 2.9.3-15 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3202
DLA-226-1
DLA-226-2
DLA-238-1
DSA-3266-1
DSA-3268-1
DSA-3268-2
MGASA-2015-0239
OPENSUSE-SU-2024:10378-1
SUSE-SU-2015:1024-1
SUSE-SU-2015:1053-1
SUSE-SU-2015_1024-1
SUSE-SU-2015_1053-1
USN-2617-1
USN-2617-2
USN-2617-3

Affected Products

Fuse
Suse
Ubuntu