Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3879

Опубликовано: 02 нояб. 2010
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.

Отчет

The Red Hat Security Response Team has rated this issue as having low security impact. On Red Hat Enterprise Linux 5 and 6, a user must be a member of the 'fuse' group in order to use FUSE. Due to the risks associated with fixing this bug on Red Hat Enterprise Linux 5, and because of the group restrictions in place, we currently have no plans to fix this flaw in Red Hat Enterprise Linux 5.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5fuseWill not fix
Red Hat Enterprise Linux 5util-linuxWill not fix
Red Hat Enterprise Linux 6util-linux-ngAffected
Red Hat Enterprise Linux 6fuseFixedRHSA-2011:108320.07.2011

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=651183fuse: unprivileged user can unmount arbitrary locations via symlink attack

EPSS

Процентиль: 84%
0.02202
Низкий

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.

nvd
больше 14 лет назад

FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.

debian
больше 14 лет назад

FUSE, possibly 2.8.5 and earlier, allows local users to create mtab en ...

github
больше 3 лет назад

FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.

oracle-oval
около 14 лет назад

ELSA-2011-1083: fuse security update (MODERATE)

EPSS

Процентиль: 84%
0.02202
Низкий

2.6 Low

CVSS2