CVE-2015-3202

fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.6 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
Affected Products (NVD)
VendorProductVersion
debiandebian_linux
8.0
fuse_projectfuse
𝑥
≤ 2.9.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
fuse
bookworm
2.9.9-6
fixed
bullseye
2.9.9-5
fixed
sid
2.9.9-9
fixed
trixie
2.9.9-9
fixed
ntfs-3g
bookworm
1:2022.10.3-1
fixed
bullseye
1:2017.3.23AR.3-4+deb11u4
fixed
bullseye (security)
1:2017.3.23AR.3-4+deb11u3
fixed
sid
1:2022.10.3-5
fixed
trixie
1:2022.10.3-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
fuse
precise
Fixed 2.8.6-2ubuntu2.1
released
trusty
Fixed 2.9.2-4ubuntu4.14.04.1
released
utopic
Fixed 2.9.2-4ubuntu4.14.10.1
released
vivid
Fixed 2.9.2-4ubuntu4.15.04.1
released
ntfs-3g
precise
not-affected
trusty
not-affected
utopic
not-affected
vivid
Fixed 1:2014.2.15AR.3-1ubuntu0.2
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
fuse
suse enterprise desktop 15
2.9.7-1.49
fixed
suse enterprise desktop 15 SP1
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP2
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP3
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP4
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP5
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP6
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP7
2.9.7-3.3.1
fixed
suse enterprise sap 12
2.9.3-5.1
fixed
suse enterprise sap 12 SP5
2.9.3-6.3.1
fixed
suse enterprise sap 15
2.9.7-1.49
fixed
suse enterprise sap 15 SP1
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP2
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP3
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP4
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP5
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP6
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP7
2.9.7-3.3.1
fixed
suse enterprise server 12
2.9.3-5.1
fixed
suse enterprise server 12 SP1
2.9.3-5.1
fixed
suse enterprise server 12 SP2
2.9.3-5.1
fixed
suse enterprise server 12 SP3
2.9.3-5.1
fixed
suse enterprise server 12 SP4
2.9.3-6.3.1
fixed
suse enterprise server 12 SP5
2.9.3-6.3.1
fixed
suse enterprise server 15
2.9.7-1.49
fixed
suse enterprise server 15 SP1
2.9.7-3.3.1
fixed
suse enterprise server 15 SP2
2.9.7-3.3.1
fixed
suse enterprise server 15 SP3
2.9.7-3.3.1
fixed
suse enterprise server 15 SP4
2.9.7-3.3.1
fixed
suse enterprise server 15 SP5
2.9.7-3.3.1
fixed
suse enterprise server 15 SP6
2.9.7-3.3.1
fixed
suse enterprise server 15 SP7
2.9.7-3.3.1
fixed
fuse-devel
suse enterprise desktop 15
2.9.7-1.49
fixed
suse enterprise desktop 15 SP1
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP2
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP3
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP4
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP5
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP6
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP7
2.9.7-3.3.1
fixed
suse enterprise sap 15
2.9.7-1.49
fixed
suse enterprise sap 15 SP1
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP2
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP3
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP4
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP5
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP6
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP7
2.9.7-3.3.1
fixed
suse enterprise server 15
2.9.7-1.49
fixed
suse enterprise server 15 SP1
2.9.7-3.3.1
fixed
suse enterprise server 15 SP2
2.9.7-3.3.1
fixed
suse enterprise server 15 SP3
2.9.7-3.3.1
fixed
suse enterprise server 15 SP4
2.9.7-3.3.1
fixed
suse enterprise server 15 SP5
2.9.7-3.3.1
fixed
suse enterprise server 15 SP6
2.9.7-3.3.1
fixed
suse enterprise server 15 SP7
2.9.7-3.3.1
fixed
fuse-doc
suse enterprise desktop 15
2.9.7-1.49
fixed
suse enterprise desktop 15 SP1
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP2
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP3
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP4
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP5
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP6
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP7
2.9.7-3.3.1
fixed
suse enterprise sap 15
2.9.7-1.49
fixed
suse enterprise sap 15 SP1
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP2
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP3
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP4
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP5
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP6
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP7
2.9.7-3.3.1
fixed
suse enterprise server 15
2.9.7-1.49
fixed
suse enterprise server 15 SP1
2.9.7-3.3.1
fixed
suse enterprise server 15 SP2
2.9.7-3.3.1
fixed
suse enterprise server 15 SP3
2.9.7-3.3.1
fixed
suse enterprise server 15 SP4
2.9.7-3.3.1
fixed
suse enterprise server 15 SP5
2.9.7-3.3.1
fixed
suse enterprise server 15 SP6
2.9.7-3.3.1
fixed
suse enterprise server 15 SP7
2.9.7-3.3.1
fixed
libfuse2
suse enterprise desktop 15
2.9.7-1.49
fixed
suse enterprise desktop 15 SP1
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP2
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP3
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP4
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP5
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP6
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP7
2.9.7-3.3.1
fixed
suse enterprise sap 12
2.9.3-5.1
fixed
suse enterprise sap 12 SP5
2.9.3-6.3.1
fixed
suse enterprise sap 15
2.9.7-1.49
fixed
suse enterprise sap 15 SP1
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP2
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP3
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP4
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP5
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP6
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP7
2.9.7-3.3.1
fixed
suse enterprise server 12
2.9.3-5.1
fixed
suse enterprise server 12 SP1
2.9.3-5.1
fixed
suse enterprise server 12 SP2
2.9.3-5.1
fixed
suse enterprise server 12 SP3
2.9.3-5.1
fixed
suse enterprise server 12 SP4
2.9.3-6.3.1
fixed
suse enterprise server 12 SP5
2.9.3-6.3.1
fixed
suse enterprise server 15
2.9.7-1.49
fixed
suse enterprise server 15 SP1
2.9.7-3.3.1
fixed
suse enterprise server 15 SP2
2.9.7-3.3.1
fixed
suse enterprise server 15 SP3
2.9.7-3.3.1
fixed
suse enterprise server 15 SP4
2.9.7-3.3.1
fixed
suse enterprise server 15 SP5
2.9.7-3.3.1
fixed
suse enterprise server 15 SP6
2.9.7-3.3.1
fixed
suse enterprise server 15 SP7
2.9.7-3.3.1
fixed
libulockmgr1
suse enterprise desktop 15
2.9.7-1.49
fixed
suse enterprise desktop 15 SP1
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP2
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP3
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP4
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP5
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP6
2.9.7-3.3.1
fixed
suse enterprise desktop 15 SP7
2.9.7-3.3.1
fixed
suse enterprise sap 15
2.9.7-1.49
fixed
suse enterprise sap 15 SP1
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP2
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP3
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP4
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP5
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP6
2.9.7-3.3.1
fixed
suse enterprise sap 15 SP7
2.9.7-3.3.1
fixed
suse enterprise server 15
2.9.7-1.49
fixed
suse enterprise server 15 SP1
2.9.7-3.3.1
fixed
suse enterprise server 15 SP2
2.9.7-3.3.1
fixed
suse enterprise server 15 SP3
2.9.7-3.3.1
fixed
suse enterprise server 15 SP4
2.9.7-3.3.1
fixed
suse enterprise server 15 SP5
2.9.7-3.3.1
fixed
suse enterprise server 15 SP6
2.9.7-3.3.1
fixed
suse enterprise server 15 SP7
2.9.7-3.3.1
fixed
Common Weakness Enumeration
References