CVE-2011-0543: Low severity foreman vulnerability
Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0543?
CVE-2011-0543 is considered a medium severity vulnerability, allowing local users to bypass access restrictions.
How do I fix CVE-2011-0543?
To fix CVE-2011-0543, update to a version of fuse greater than 2.8.5 or ensure that util-linux supports the --no-canonicalize option.
What types of attacks can CVE-2011-0543 be exploited for?
CVE-2011-0543 can be exploited for symlink attacks, which allow users to unmount arbitrary directories.
Which versions of fuse are affected by CVE-2011-0543?
Versions of fuse up to 2.8.5 are affected by CVE-2011-0543.
Can CVE-2011-0543 be mitigated through configuration changes?
Mitigating CVE-2011-0543 through configuration changes is not feasible; upgrading to a patched version of fuse is necessary.