First published: Fri Sep 02 2011(Updated: )
fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fuse | <=2.8.5 | |
Fuse | =1.9 | |
Fuse | =2.0-pre0 | |
Fuse | =2.0-pre1 | |
Fuse | =2.1 | |
Fuse | =2.2 | |
Fuse | =2.2.1 | |
Fuse | =2.3-pre | |
Fuse | =2.3-rc1 | |
Fuse | =2.3.0 | |
Fuse | =2.4.0 | |
Fuse | =2.4.1 | |
Fuse | =2.4.2 | |
Fuse | =2.5.0 | |
Fuse | =2.5.1 | |
Fuse | =2.5.2 | |
Fuse | =2.5.3 | |
Fuse | =2.6.0 | |
Fuse | =2.6.1 | |
Fuse | =2.6.3 | |
Fuse | =2.6.5 | |
Fuse | =2.7.0 | |
Fuse | =2.7.1 | |
Fuse | =2.7.2 | |
Fuse | =2.7.3 | |
Fuse | =2.7.4 | |
Fuse | =2.7.5 | |
Fuse | =2.7.6 | |
Fuse | =2.8.0 | |
Fuse | =2.8.1 | |
Fuse | =2.8.2 | |
Fuse | =2.8.3 | |
Fuse | =2.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0542 is a vulnerability in fusermount that allows local users to unmount arbitrary directories due to not performing a chdir to / before mount or umount.
CVE-2011-0542 affects Fusermount in fuse versions 2.8.5 and earlier, along with version 1.9 and specific pre-release and release versions of fuse.
CVE-2011-0542 is categorized as a moderate severity vulnerability due to its potential impact on local user capabilities.
To fix CVE-2011-0542, upgrade fuse to a version later than 2.8.5 or any version after the identified vulnerabilities.
Local users on systems running vulnerable versions of fuse are impacted by CVE-2011-0542 as they can exploit this vulnerability.