CVE-2015-3202
published 2015-07-02CVE-2015-3202: fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write…
PriorityP423low3.6CVSS 2.0
AVLACLAuNCNIPAP
EXPLOIT
EPSS
1.01%
59.1th percentile
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | fuse | < fuse 2.9.3-16 (bookworm) | fuse 2.9.3-16 (bookworm) |
| debian | ntfs-3g | < fuse 2.9.3-16 (bookworm) | fuse 2.9.3-16 (bookworm) |
| fuse_project | fuse | <= 2.9.2 | — |
| redhat | fuse | >= 0 < 2.9.3-16 | 2.9.3-16 |
| redhat | fuse | >= 0 < 2.9.3-16 | 2.9.3-16 |
| redhat | fuse | >= 0 < 2.9.3-16 | 2.9.3-16 |
| tuxera | ntfs-3g | >= 0 < 1:2014.2.15AR.3-3 | 1:2014.2.15AR.3-3 |
| tuxera | ntfs-3g | >= 0 < 1:2014.2.15AR.3-3 | 1:2014.2.15AR.3-3 |
| tuxera | ntfs-3g | >= 0 < 1:2014.2.15AR.3-3 | 1:2014.2.15AR.3-3 |
| tuxera | ntfs-3g | >= 0 < 1:2014.2.15AR.3-3 | 1:2014.2.15AR.3-3 |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.6LOW
vendor_debian3.6LOW
vendor_redhat3.6LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NTFS-3G vulnerability
vendor_ubuntu·2015-05-27
CVE-2015-3202 NTFS-3G vulnerability
Title: NTFS-3G vulnerability
Summary: NTFS-3G could be made to overwrite files as the administrator.
USN-2617-1 fixed a vulnerability in NTFS-3G. The original patch did not
completely address the issue. This update fixes the problem.
Original advisory details:
Tavis Ormandy discovered that FUSE incorrectly filtered environment
variables. A local attacker could use this issue to gain administrative
privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
NTFS-3G vulnerability
vendor_ubuntu·2015-05-22
CVE-2015-3202 NTFS-3G vulnerability
Title: NTFS-3G vulnerability
Summary: NTFS-3G could be made to overwrite files as the administrator.
USN-2617-1 fixed a vulnerability in FUSE. This update provides the
corresponding fix for the embedded FUSE copy in NTFS-3G.
Original advisory details:
Tavis Ormandy discovered that FUSE incorrectly filtered environment
variables. A local attacker could use this issue to gain administrative
privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
FUSE vulnerability
vendor_ubuntu·2015-05-21
CVE-2015-3202 FUSE vulnerability
Title: FUSE vulnerability
Summary: FUSE could be made to overwrite files as the administrator.
Tavis Ormandy discovered that FUSE incorrectly filtered environment
variables. A local attacker could use this issue to gain administrative
privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
fuse: incorrect filtering of environment variables leading to privilege escalation
vendor_redhat·2015-05-21·CVSS 3.6
CVE-2015-3202 [LOW] CWE-20 fuse: incorrect filtering of environment variables leading to privilege escalation
fuse: incorrect filtering of environment variables leading to privilege escalation
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
It was discovered that fusermount failed to properly sanitize its environment before executing mount and umount commands. A local user could possibly use this flaw to escalate their privileges on the system.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https:
Debian
CVE-2015-3202: fuse - fusermount in FUSE before 2.9.3-15 does not properly clear the environment befor...
vendor_debian·2015·CVSS 3.6
CVE-2015-3202 [LOW] CVE-2015-3202: fuse - fusermount in FUSE before 2.9.3-15 does not properly clear the environment befor...
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
Scope: local
bookworm: resolved (fixed in 2.9.3-16)
bullseye: resolved (fixed in 2.9.3-16)
sid: resolved (fixed in 2.9.3-16)
trixie: resolved (fixed in 2.9.3-16)
GHSA
GHSA-32rg-hvr8-56hx: fusermount in FUSE before 2
ghsa_unreviewed·2022-05-17
CVE-2015-3202 [LOW] GHSA-32rg-hvr8-56hx: fusermount in FUSE before 2
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
OSV
CVE-2015-3202: fusermount in FUSE before 2
osv·2015-07-02·CVSS 3.6
CVE-2015-3202 [LOW] CVE-2015-3202: fusermount in FUSE before 2
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
No detection rules found.
Bugzilla
CVE-2015-3202 ntfs-3g: fuse: incorrect filtering of environment variables leading to privilege escalation [epel-all]
bugzilla·2015-05-22·CVSS 3.6
CVE-2015-3202 [LOW] CVE-2015-3202 ntfs-3g: fuse: incorrect filtering of environment variables leading to privilege escalation [epel-all]
CVE-2015-3202 ntfs-3g: fuse: incorrect filtering of environment variables leading to privilege escalation [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
Bugzilla
CVE-2015-3202 ntfs-3g: fuse: incorrect filtering of environment variables leading to privilege escalation [fedora-all]
bugzilla·2015-05-22·CVSS 3.6
CVE-2015-3202 [LOW] CVE-2015-3202 ntfs-3g: fuse: incorrect filtering of environment variables leading to privilege escalation [fedora-all]
CVE-2015-3202 ntfs-3g: fuse: incorrect filtering of environment variables leading to privilege escalation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2015-3202 fuse: incorrect filtering of environment variables leading to privilege escalation [fedora-all]
bugzilla·2015-05-22·CVSS 3.6
CVE-2015-3202 [LOW] CVE-2015-3202 fuse: incorrect filtering of environment variables leading to privilege escalation [fedora-all]
CVE-2015-3202 fuse: incorrect filtering of environment variables leading to privilege escalation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2015-3202 fuse: incorrect filtering of environment variables leading to privilege escalation
bugzilla·2015-05-22·CVSS 3.6
CVE-2015-3202 [LOW] CVE-2015-3202 fuse: incorrect filtering of environment variables leading to privilege escalation
CVE-2015-3202 fuse: incorrect filtering of environment variables leading to privilege escalation
It was foudn that FUSE, a Filesystem in USErspace, did not properly sanitize environment variables before executing a mount or umount operation with elevated privileges. A local attacker could use this flaw to overwrite arbitrary files on the system or escalate their privileges.
Additional details:
http://seclists.org/oss-sec/2015/q2/520
Patch proposed on distros is attached.
Discussion:
Created attachment 1028606
CVE-2015-3202.patch
---
Created ntfs-3g tracking bugs for this issue:
Affects: fedora-all [bug 1224105]
Affects: epel-all [bug 1224108]
---
Created fuse tracking bugs for this issue:
Affects: fedora-all [bug 1224104]
---
Upstream commit:
http://sourceforge.net/p/fuse/fus
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159298.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159543.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159683.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159831.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160094.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160106.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00007.htmlhttp://packetstormsecurity.com/files/132021/Fuse-Local-Privilege-Escalation.htmlhttp://www.debian.org/security/2015/dsa-3266http://www.debian.org/security/2015/dsa-3268http://www.openwall.com/lists/oss-security/2015/05/21/9http://www.securityfocus.com/bid/74765http://www.securitytracker.com/id/1032386http://www.ubuntu.com/usn/USN-2617-1http://www.ubuntu.com/usn/USN-2617-2http://www.ubuntu.com/usn/USN-2617-3https://gist.github.com/taviso/ecb70eb12d461dd85cbahttps://security.gentoo.org/glsa/201603-04https://security.gentoo.org/glsa/201701-19https://twitter.com/taviso/status/601370527437967360https://www.exploit-db.com/exploits/37089/http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159298.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159543.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159683.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159831.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160094.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160106.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00007.htmlhttp://packetstormsecurity.com/files/132021/Fuse-Local-Privilege-Escalation.htmlhttp://www.debian.org/security/2015/dsa-3266http://www.debian.org/security/2015/dsa-3268http://www.openwall.com/lists/oss-security/2015/05/21/9http://www.securityfocus.com/bid/74765http://www.securitytracker.com/id/1032386http://www.ubuntu.com/usn/USN-2617-1http://www.ubuntu.com/usn/USN-2617-2http://www.ubuntu.com/usn/USN-2617-3https://gist.github.com/taviso/ecb70eb12d461dd85cbahttps://security.gentoo.org/glsa/201603-04https://security.gentoo.org/glsa/201701-19https://twitter.com/taviso/status/601370527437967360https://www.exploit-db.com/exploits/37089/
2015-07-02
Published