CVE-2010-3879
published 2011-01-22CVE-2010-3879: FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink…
PriorityP338medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EXPLOIT
EPSS
9.85%
95.0th percentile
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fuse | < fuse 2.8.5-1 (bookworm) | fuse 2.8.5-1 (bookworm) |
| libfuse_project | libfuse | <= 2.8.5 | — |
| redhat | fuse | >= 0 < 2.8.5-1 | 2.8.5-1 |
| redhat | fuse | >= 0 < 2.8.5-1 | 2.8.5-1 |
| redhat | fuse | >= 0 < 2.8.5-1 | 2.8.5-1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
util-linux update
vendor_ubuntu·2011-01-19
CVE-2010-3879 util-linux update
Title: util-linux update
USN-1045-1 fixed vulnerabilities in FUSE. This update to util-linux adds
support for new options required by the FUSE update.
Original advisory details:
It was discovered that FUSE could be tricked into incorrectly updating the
mtab file when mounting filesystems. A local attacker, with access to use
FUSE, could unmount arbitrary locations, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
FUSE vulnerability
vendor_ubuntu·2011-01-19
CVE-2010-3879 FUSE vulnerability
Title: FUSE vulnerability
It was discovered that FUSE could be tricked into incorrectly updating the
mtab file when mounting filesystems. A local attacker, with access to use
FUSE, could unmount arbitrary locations, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
fuse: unprivileged user can unmount arbitrary locations via symlink attack
vendor_redhat·2010-11-02·CVSS 3.3
CVE-2010-3879 [LOW] fuse: unprivileged user can unmount arbitrary locations via symlink attack
fuse: unprivileged user can unmount arbitrary locations via symlink attack
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact. On Red Hat Enterprise Linux 5 and 6, a user must be a member of the 'fuse' group in order to use FUSE. Due to the risks associated with fixing this bug on Red Hat Enterprise Linux 5, and because of the group restrictions in place, we currently have no plans to fix this flaw in Red Hat Enterprise Linux 5.
Package: fuse (Red Hat Enterprise Linux 5) -
Debian
CVE-2010-3879: fuse - FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with...
vendor_debian·2010·CVSS 3.3
CVE-2010-3879 [LOW] CVE-2010-3879: fuse - FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with...
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
Scope: local
bookworm: resolved (fixed in 2.8.5-1)
bullseye: resolved (fixed in 2.8.5-1)
sid: resolved (fixed in 2.8.5-1)
trixie: resolved (fixed in 2.8.5-1)
GHSA
GHSA-9qwx-j72c-6hr4: FUSE, possibly 2
ghsa_unreviewed·2022-05-13·CVSS 3.3
CVE-2010-3879 [LOW] CWE-59 GHSA-9qwx-j72c-6hr4: FUSE, possibly 2
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
OSV
CVE-2010-3879: FUSE, possibly 2
osv·2011-01-22·CVSS 3.3
CVE-2010-3879 [LOW] CVE-2010-3879: FUSE, possibly 2
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
No detection rules found.
Bugzilla
CVE-2010-3879 fuse: unprivileged user can unmount arbitrary locations via symlink attack [fedora-all]
bugzilla·2011-01-27·CVSS 5.8
CVE-2010-3879 [MEDIUM] CVE-2010-3879 fuse: unprivileged user can unmount arbitrary locations via symlink attack [fedora-all]
CVE-2010-3879 fuse: unprivileged user can unmount arbitrary locations via symlink attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=651183
Please note:
Bugzilla
CVE-2010-3879 fuse: unprivileged user can unmount arbitrary locations via symlink attack [fedora-all]
bugzilla·2011-01-27·CVSS 5.8
CVE-2010-3879 [MEDIUM] CVE-2010-3879 fuse: unprivileged user can unmount arbitrary locations via symlink attack [fedora-all]
CVE-2010-3879 fuse: unprivileged user can unmount arbitrary locations via symlink attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=651183
Please note:
Bugzilla
CVE-2010-3879 CVE-2011-0541 CVE-2011-0542 CVE-2011-0543 fuse: unprivileged user can unmount arbitrary locations via symlink attack
bugzilla·2010-11-08·CVSS 5.8
CVE-2010-3879 [MEDIUM] CVE-2010-3879 CVE-2011-0541 CVE-2011-0542 CVE-2011-0543 fuse: unprivileged user can unmount arbitrary locations via symlink attack
CVE-2010-3879 CVE-2011-0541 CVE-2011-0542 CVE-2011-0543 fuse: unprivileged user can unmount arbitrary locations via symlink attack
It was reported [1],[2] that the fusermount tool was vulnerable to a race condition between mounting a user filesystem and updating mtab using the standard mount command. If a user were able to win the race, the real mount entry and the mtab entry would differ, making the fuse-mounted filesystem not unmountable by an unprivileged user. Crafted mtab entries can then be used to trick fusermount into believing that a certain part of the filesystem is a user-space filesystem, and will unmount what should be a privileged filesystem (as demonstrated by unmounting /proc).
According to the SUSE bug report [3], this would affect fuse versions before 2.8.2 or util-linu
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=602333http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053792.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2010-November/077247.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://openwall.com/lists/oss-security/2010/11/04/8http://openwall.com/lists/oss-security/2010/11/05/2http://osvdb.org/70520http://secunia.com/advisories/42961http://secunia.com/advisories/42965http://www.halfdog.net/Security/FuseTimerace/http://www.mandriva.com/security/advisories?name=MDVSA-2013:155http://www.securityfocus.com/bid/44623http://www.ubuntu.com/usn/USN-1045-1http://www.ubuntu.com/usn/USN-1045-2http://www.vupen.com/english/advisories/2011/0181http://www.vupen.com/english/advisories/2011/0302https://bugs.launchpad.net/bugs/670622https://bugzilla.novell.com/show_bug.cgi?id=651598https://bugzilla.redhat.com/show_bug.cgi?id=651183https://exchange.xforce.ibmcloud.com/vulnerabilities/62986http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=602333http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053792.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2010-November/077247.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://openwall.com/lists/oss-security/2010/11/04/8http://openwall.com/lists/oss-security/2010/11/05/2http://osvdb.org/70520http://secunia.com/advisories/42961http://secunia.com/advisories/42965http://www.halfdog.net/Security/FuseTimerace/http://www.mandriva.com/security/advisories?name=MDVSA-2013:155http://www.securityfocus.com/bid/44623http://www.ubuntu.com/usn/USN-1045-1http://www.ubuntu.com/usn/USN-1045-2http://www.vupen.com/english/advisories/2011/0181http://www.vupen.com/english/advisories/2011/0302https://bugs.launchpad.net/bugs/670622https://bugzilla.novell.com/show_bug.cgi?id=651598https://bugzilla.redhat.com/show_bug.cgi?id=651183https://exchange.xforce.ibmcloud.com/vulnerabilities/62986
2011-01-22
Published