Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2015-3202Improper Input Validation in Project Fuse

Severity
3.6LOWNVD
EPSS
0.3%
top 43.53%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 2
Latest updateMay 17

Description

fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.

CVSS vector

AV:L/AC:L/C:N/I:P/A:PExploitability: 3.9 | Impact: 4.9

Affected Packages3 packages

Debianredhat/fuse< 2.9.3-16+2
Debiantuxera/ntfs-3g< 1:2014.2.15AR.3-3+3

Also affects: Debian Linux 8.0

🔴Vulnerability Details

3
GHSA
GHSA-32rg-hvr8-56hx: fusermount in FUSE before 22022-05-17
CVEList
CVE-2015-3202: fusermount in FUSE before 22015-07-02
OSV
CVE-2015-3202: fusermount in FUSE before 22015-07-02

💥Exploits & PoCs

1
Exploit-DB
Fuse 2.9.3-15 - Local Privilege Escalation2015-05-23

📋Vendor Advisories

5
Ubuntu
NTFS-3G vulnerability2015-05-27
Ubuntu
NTFS-3G vulnerability2015-05-22
Ubuntu
FUSE vulnerability2015-05-21
Red Hat
fuse: incorrect filtering of environment variables leading to privilege escalation2015-05-21
Debian
CVE-2015-3202: fuse - fusermount in FUSE before 2.9.3-15 does not properly clear the environment befor...2015

💬Community

4
Bugzilla
CVE-2015-3202 ntfs-3g: fuse: incorrect filtering of environment variables leading to privilege escalation [epel-all]2015-05-22
Bugzilla
CVE-2015-3202 ntfs-3g: fuse: incorrect filtering of environment variables leading to privilege escalation [fedora-all]2015-05-22
Bugzilla
CVE-2015-3202 fuse: incorrect filtering of environment variables leading to privilege escalation [fedora-all]2015-05-22
Bugzilla
CVE-2015-3202 fuse: incorrect filtering of environment variables leading to privilege escalation2015-05-22
CVE-2015-3202 — Improper Input Validation | cvebase