CVE-2011-0541
fuse: unprivileged user can unmount arbitrary locations via symlink attack
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
Fuse v2.8.5 y anteriores no se comporta de forma adecuada cuando /etc/mtlab no puede ser actualizado, lo que permite a usuarios locales desmontar directorios de su elección a través de un ataque de enlaces simbólicos.
FUSE can implement a fully functional file system in a user-space program. These packages provide the mount utility, fusermount, the tool used to mount FUSE file systems. Multiple flaws were found in the way fusermount handled the mounting and unmounting of directories when symbolic links were present. A local user in the fuse group could use these flaws to unmount file systems, which they would otherwise not be able to unmount and that were not mounted using FUSE, via a symbolic link attack.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-01-20 CVE Reserved
- 2011-02-28 CVE Published
- 2024-08-06 CVE Updated
- 2025-05-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://fuse.git.sourceforge.net/git/gitweb.cgi?p=fuse/fuse%3Ba=commit%3Bh=bf5ffb5fd8558bd799791834def431c0cee5a11f | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2011/02/02/2 | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2011/02/03/5 | 2023-02-13 | |
http://www.openwall.com/lists/oss-security/2011/02/08/4 | 2023-02-13 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2011-0541 | 2011-07-20 | |
https://bugzilla.redhat.com/show_bug.cgi?id=651183 | 2011-07-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | <= 2.8.5 Search vendor "Fuse" for product "Fuse" and version " <= 2.8.5" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 1.9 Search vendor "Fuse" for product "Fuse" and version "1.9" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.0 Search vendor "Fuse" for product "Fuse" and version "2.0" | pre0 |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.0 Search vendor "Fuse" for product "Fuse" and version "2.0" | pre1 |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.1 Search vendor "Fuse" for product "Fuse" and version "2.1" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.2 Search vendor "Fuse" for product "Fuse" and version "2.2" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.2.1 Search vendor "Fuse" for product "Fuse" and version "2.2.1" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.3 Search vendor "Fuse" for product "Fuse" and version "2.3" | pre |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.3 Search vendor "Fuse" for product "Fuse" and version "2.3" | rc1 |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.3.0 Search vendor "Fuse" for product "Fuse" and version "2.3.0" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.4.0 Search vendor "Fuse" for product "Fuse" and version "2.4.0" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.4.1 Search vendor "Fuse" for product "Fuse" and version "2.4.1" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.4.2 Search vendor "Fuse" for product "Fuse" and version "2.4.2" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.5.0 Search vendor "Fuse" for product "Fuse" and version "2.5.0" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.5.1 Search vendor "Fuse" for product "Fuse" and version "2.5.1" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.5.2 Search vendor "Fuse" for product "Fuse" and version "2.5.2" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.5.3 Search vendor "Fuse" for product "Fuse" and version "2.5.3" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.6.0 Search vendor "Fuse" for product "Fuse" and version "2.6.0" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.6.1 Search vendor "Fuse" for product "Fuse" and version "2.6.1" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.6.3 Search vendor "Fuse" for product "Fuse" and version "2.6.3" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.6.5 Search vendor "Fuse" for product "Fuse" and version "2.6.5" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.7.0 Search vendor "Fuse" for product "Fuse" and version "2.7.0" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.7.1 Search vendor "Fuse" for product "Fuse" and version "2.7.1" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.7.2 Search vendor "Fuse" for product "Fuse" and version "2.7.2" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.7.3 Search vendor "Fuse" for product "Fuse" and version "2.7.3" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.7.4 Search vendor "Fuse" for product "Fuse" and version "2.7.4" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.7.5 Search vendor "Fuse" for product "Fuse" and version "2.7.5" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.7.6 Search vendor "Fuse" for product "Fuse" and version "2.7.6" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.8.0 Search vendor "Fuse" for product "Fuse" and version "2.8.0" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.8.1 Search vendor "Fuse" for product "Fuse" and version "2.8.1" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.8.2 Search vendor "Fuse" for product "Fuse" and version "2.8.2" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.8.3 Search vendor "Fuse" for product "Fuse" and version "2.8.3" | - |
Affected
| ||||||
Fuse Search vendor "Fuse" | Fuse Search vendor "Fuse" for product "Fuse" | 2.8.4 Search vendor "Fuse" for product "Fuse" and version "2.8.4" | - |
Affected
|