CVE-2010-0789: Low severity fuse FUSE vulnerability
fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0789?
CVE-2010-0789 has been assigned a medium severity due to the potential for local users to unmount arbitrary FUSE filesystem shares.
How do I fix CVE-2010-0789?
To fix CVE-2010-0789, upgrade to FUSE version 2.7.5 or later, or 2.8.2 or later, as these versions contain the necessary security fixes.
Who is affected by CVE-2010-0789?
CVE-2010-0789 affects local users on systems running vulnerable versions of FUSE prior to 2.7.5 and 2.8.2.
What is the nature of the attack related to CVE-2010-0789?
The attack involves a symlink manipulation to unmount a FUSE filesystem by exploiting the file permission handling in fusermount.
Are there any workarounds for CVE-2010-0789?
A possible workaround for CVE-2010-0789 is to restrict access permissions for local users to sensitive filesystems until the software is patched.