CVE-2011-0543
published 2011-09-02CVE-2011-0543: Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to…
PriorityP411low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.33%
25.3th percentile
Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fuse | < fuse 2.8.5-1 (bookworm) | fuse 2.8.5-1 (bookworm) |
| fuse | fuse | <= 2.8.5 | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2g2x-4qqh-7m58: Certain legacy functionality in fusermount in fuse 2
ghsa_unreviewed·2022-05-17
CVE-2011-0543 [LOW] GHSA-2g2x-4qqh-7m58: Certain legacy functionality in fusermount in fuse 2
Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.
OSV
CVE-2011-0543: Certain legacy functionality in fusermount in fuse 2
osv·2011-09-02·CVSS 3.3
CVE-2011-0543 [LOW] CVE-2011-0543: Certain legacy functionality in fusermount in fuse 2
Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.
Ubuntu
FUSE vulnerabilities
vendor_ubuntu·2011-02-28
CVE-2011-0541 FUSE vulnerabilities
Title: FUSE vulnerabilities
It was discovered that FUSE would incorrectly follow symlinks when checking
mountpoints under certain conditions. A local attacker, with access to use
FUSE, could unmount arbitrary locations, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2011-0543: fuse - Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-...
vendor_debian·2011·CVSS 3.3
CVE-2011-0543 [LOW] CVE-2011-0543: fuse - Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-...
Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.
Scope: local
bookworm: resolved (fixed in 2.8.5-1)
bullseye: resolved (fixed in 2.8.5-1)
sid: resolved (fixed in 2.8.5-1)
trixie: resolved (fixed in 2.8.5-1)
Red Hat
fuse: unprivileged user can unmount arbitrary locations via symlink attack
vendor_redhat·2010-11-02·CVSS 3.3
CVE-2011-0543 [LOW] fuse: unprivileged user can unmount arbitrary locations via symlink attack
fuse: unprivileged user can unmount arbitrary locations via symlink attack
Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact. On Red Hat Enterprise Linux 5 and 6, a user must be a member of the 'fuse' group in order to use FUSE. Due to the risks associated with fixing this bug on Red Hat Enterprise Linux 5, and because of the group restrictions in place, we currently have no plans to fix this flaw in Red Hat Enterprise Linux 5.
Package: fuse (Red Hat Enterprise Linux 5) - Will not fix
Package: uti
No detection rules found.
No public exploits indexed.
http://fuse.git.sourceforge.net/git/gitweb.cgi?p=fuse/fuse%3Ba=commit%3Bh=cbd3a2a84068aae6e3fe32939d88470d712dbf47http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://www.openwall.com/lists/oss-security/2011/02/02/2http://www.openwall.com/lists/oss-security/2011/02/03/5http://www.openwall.com/lists/oss-security/2011/02/08/4http://fuse.git.sourceforge.net/git/gitweb.cgi?p=fuse/fuse%3Ba=commit%3Bh=cbd3a2a84068aae6e3fe32939d88470d712dbf47http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://www.openwall.com/lists/oss-security/2011/02/02/2http://www.openwall.com/lists/oss-security/2011/02/03/5http://www.openwall.com/lists/oss-security/2011/02/08/4
2011-09-02
Published