CVE-2015-3202
Last modified
CVE-2015-3202 is a vulnerability of currently unknown severity. fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 8.0 |
| Fuse Project | Fuse | <= 2.9.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-3202?
How severe is CVE-2015-3202?
How do I fix CVE-2015-3202?
Are you affected by CVE-2015-3202?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
