CVE-2015-3202: Low severity debian linux vulnerability
Published Jul 2, 2015
·Updated
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNTMTAB environment variable that is used by mount's debugging feature.
Affected Software
2 affected components
Debian Debian Linux=8.0
Fuse Project Fuse<=2.9.2
Event History
Jul 2, 2015
CVE Published
via MITRE·09:16 PM
Data Sourced
via MITRE·09:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3202?
CVE-2015-3202 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2015-3202?
To fix CVE-2015-3202, upgrade to FUSE version 2.9.3-15 or later.
3
What software is affected by CVE-2015-3202?
CVE-2015-3202 affects FUSE versions up to 2.9.2 and Debian GNU/Linux 8.0.
4
What threats are posed by CVE-2015-3202?
CVE-2015-3202 allows local users to write to arbitrary files due to improper handling of the LIBMOUNT_MTAB environment variable.
5
Who is impacted by CVE-2015-3202?
Local users on systems running affected versions of FUSE and Debian GNU/Linux may be impacted by CVE-2015-3202.