CVE-2010-3879

FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
VendorProductVersion
libfuse_projectlibfuse
𝑥
≤ 2.8.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
fuse
bullseye
2.9.9-5
fixed
squeeze
no-dsa
bookworm
2.9.9-6
fixed
sid
2.9.9-9
fixed
trixie
2.9.9-9
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
fuse
maverick
Fixed 2.8.4-1ubuntu1.1
released
lucid
Fixed 2.8.1-1.1ubuntu2.2
released
karmic
Fixed 2.7.4-1.1ubuntu4.4
released
hardy
Fixed 2.7.2-1ubuntu2.2
released
dapper
ignored
util-linux
maverick
Fixed 2.17.2-0ubuntu1.10.10.1
released
lucid
Fixed 2.17.2-0ubuntu1.10.04.1
released
karmic
Fixed 2.16-1ubuntu5.1
released
hardy
Fixed 2.13.1-5ubuntu3.1
released
dapper
ignored
References