cbcvebase.
CVE-2015-3202
published 2015-07-02

CVE-2015-3202: fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write…

PriorityP423low3.6CVSS 2.0
AVLACLAuNCNIPAP
EXPLOIT
EPSS
1.01%
59.5th percentile
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianfuse< fuse 2.9.3-16 (bookworm)fuse 2.9.3-16 (bookworm)
debianntfs-3g< fuse 2.9.3-16 (bookworm)fuse 2.9.3-16 (bookworm)
fuse_projectfuse<= 2.9.2
redhatfuse>= 0 < 2.9.3-162.9.3-16
redhatfuse>= 0 < 2.9.3-162.9.3-16
redhatfuse>= 0 < 2.9.3-162.9.3-16
tuxerantfs-3g>= 0 < 1:2014.2.15AR.3-31:2014.2.15AR.3-3
tuxerantfs-3g>= 0 < 1:2014.2.15AR.3-31:2014.2.15AR.3-3
tuxerantfs-3g>= 0 < 1:2014.2.15AR.3-31:2014.2.15AR.3-3
tuxerantfs-3g>= 0 < 1:2014.2.15AR.3-31:2014.2.15AR.3-3

CVSS provenance

nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.6LOW
vendor_debian3.6LOW
vendor_redhat3.6LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.