CVE-2011-0541
published 2011-09-02CVE-2011-0541: fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink…
PriorityP49low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.32%
24.4th percentile
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fuse | < fuse 2.8.5-1 (bookworm) | fuse 2.8.5-1 (bookworm) |
| fuse | fuse | <= 2.8.5 | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c7fc-4fvh-989j: fuse 2
ghsa_unreviewed·2022-05-17
CVE-2011-0541 [LOW] CWE-59 GHSA-c7fc-4fvh-989j: fuse 2
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
OSV
CVE-2011-0541: fuse 2
osv·2011-09-02·CVSS 3.3
CVE-2011-0541 [LOW] CVE-2011-0541: fuse 2
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
Ubuntu
FUSE vulnerabilities
vendor_ubuntu·2011-02-28
CVE-2011-0541 FUSE vulnerabilities
Title: FUSE vulnerabilities
It was discovered that FUSE would incorrectly follow symlinks when checking
mountpoints under certain conditions. A local attacker, with access to use
FUSE, could unmount arbitrary locations, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2011-0541: fuse - fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated...
vendor_debian·2011·CVSS 3.3
CVE-2011-0541 [LOW] CVE-2011-0541: fuse - fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated...
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
Scope: local
bookworm: resolved (fixed in 2.8.5-1)
bullseye: resolved (fixed in 2.8.5-1)
sid: resolved (fixed in 2.8.5-1)
trixie: resolved (fixed in 2.8.5-1)
Red Hat
fuse: unprivileged user can unmount arbitrary locations via symlink attack
vendor_redhat·2010-11-02·CVSS 3.3
CVE-2011-0541 [LOW] fuse: unprivileged user can unmount arbitrary locations via symlink attack
fuse: unprivileged user can unmount arbitrary locations via symlink attack
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact. On Red Hat Enterprise Linux 5 and 6, a user must be a member of the 'fuse' group in order to use FUSE. Due to the risks associated with fixing this bug on Red Hat Enterprise Linux 5, and because of the group restrictions in place, we currently have no plans to fix this flaw in Red Hat Enterprise Linux 5.
Package: fuse (Red Hat Enterprise Linux 5) - Will not fix
Package: util-linux (Red Hat Enterprise Linux 5) - Will not fix
Package: util-linux-ng (Red Hat
No detection rules found.
No public exploits indexed.
http://fuse.git.sourceforge.net/git/gitweb.cgi?p=fuse/fuse%3Ba=commit%3Bh=bf5ffb5fd8558bd799791834def431c0cee5a11fhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://www.openwall.com/lists/oss-security/2011/02/02/2http://www.openwall.com/lists/oss-security/2011/02/03/5http://www.openwall.com/lists/oss-security/2011/02/08/4http://fuse.git.sourceforge.net/git/gitweb.cgi?p=fuse/fuse%3Ba=commit%3Bh=bf5ffb5fd8558bd799791834def431c0cee5a11fhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://www.openwall.com/lists/oss-security/2011/02/02/2http://www.openwall.com/lists/oss-security/2011/02/03/5http://www.openwall.com/lists/oss-security/2011/02/08/4
2011-09-02
Published