CVE Vulnerabilities

CVE-2015-3202

Published: Jul 02, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
7.2 IMPORTANT
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mounts debugging feature.

Affected Software

NameVendorStart VersionEnd Version
Debian_linuxDebian8.0 (including)8.0 (including)
FuseUbuntudevel*
FuseUbuntuesm-infra-legacy/trusty*
FuseUbuntuprecise*
FuseUbuntutrusty*
FuseUbuntutrusty/esm*
FuseUbuntuutopic*
FuseUbuntuvivid*
Ntfs-3gUbuntudevel*
Ntfs-3gUbuntuvivid*

References