CVE-2015-3202
02.07.2015, 21:59
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 8.0 |
| fuse_project | fuse | 𝑥 ≤ 2.9.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| fuse |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| fuse-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| fuse-doc |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libfuse2 |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libulockmgr1 |
|
Common Weakness Enumeration
References