fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fuse | Fuse | 1.9 (including) | 1.9 (including) |
Fuse | Fuse | 2.0-pre0 (including) | 2.0-pre0 (including) |
Fuse | Fuse | 2.0-pre1 (including) | 2.0-pre1 (including) |
Fuse | Fuse | 2.1 (including) | 2.1 (including) |
Fuse | Fuse | 2.2 (including) | 2.2 (including) |
Fuse | Fuse | 2.2.1 (including) | 2.2.1 (including) |
Fuse | Fuse | 2.3-pre (including) | 2.3-pre (including) |
Fuse | Fuse | 2.3-rc1 (including) | 2.3-rc1 (including) |
Fuse | Fuse | 2.3.0 (including) | 2.3.0 (including) |
Fuse | Fuse | 2.4.0 (including) | 2.4.0 (including) |
Fuse | Fuse | 2.4.1 (including) | 2.4.1 (including) |
Fuse | Fuse | 2.4.2 (including) | 2.4.2 (including) |
Fuse | Fuse | 2.5.0 (including) | 2.5.0 (including) |
Fuse | Fuse | 2.5.1 (including) | 2.5.1 (including) |
Fuse | Fuse | 2.5.2 (including) | 2.5.2 (including) |
Fuse | Fuse | 2.5.3 (including) | 2.5.3 (including) |
Fuse | Fuse | 2.6.0 (including) | 2.6.0 (including) |
Fuse | Fuse | 2.6.1 (including) | 2.6.1 (including) |
Fuse | Fuse | 2.6.3 (including) | 2.6.3 (including) |
Fuse | Fuse | 2.6.5 (including) | 2.6.5 (including) |
Fuse | Fuse | 2.7.0 (including) | 2.7.0 (including) |
Fuse | Fuse | 2.7.1 (including) | 2.7.1 (including) |
Fuse | Fuse | 2.7.2 (including) | 2.7.2 (including) |
Fuse | Fuse | 2.7.3 (including) | 2.7.3 (including) |
Fuse | Fuse | 2.7.4 (including) | 2.7.4 (including) |
Fuse | Ubuntu | dapper | * |
Fuse | Ubuntu | devel | * |
Fuse | Ubuntu | hardy | * |
Fuse | Ubuntu | intrepid | * |
Fuse | Ubuntu | jaunty | * |
Fuse | Ubuntu | karmic | * |