CVE-2015-3202
Fuse 2.9.3-15 - Local Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
fusermount en FUSE anterior a 2.9.3-15 no limpia correctamente el entorno antes de llamar a (1) mount o (2) umount como root, lo que permite a usuarios locales escribir en ficheros arbitrarios a través de una variable de entorno LIBMOUNT_MTAB manipulada que es utilizada por la característica de depuración de mount.
Tavis Ormandy discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing mount or umount with elevated privileges. A local user can take advantage of this flaw to overwrite arbitrary files and gain elevated privileges by accessing debugging features via the environment that would not normally be safe for unprivileged users.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-04-10 CVE Reserved
- 2015-05-21 CVE Published
- 2015-05-23 First Exploit
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (23)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/132021/Fuse-Local-Privilege-Escalation.html | X_refsource_misc |
|
http://www.securityfocus.com/bid/74765 | Vdb Entry | |
http://www.securitytracker.com/id/1032386 | Vdb Entry | |
https://twitter.com/taviso/status/601370527437967360 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/132021 | 2015-05-23 | |
https://www.exploit-db.com/exploits/37089 | 2024-08-06 | |
http://www.openwall.com/lists/oss-security/2015/05/21/9 | 2024-08-06 | |
https://gist.github.com/taviso/ecb70eb12d461dd85cba | 2024-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Fuse Project Search vendor "Fuse Project" | Fuse Search vendor "Fuse Project" for product "Fuse" | <= 2.9.2 Search vendor "Fuse Project" for product "Fuse" and version " <= 2.9.2" | - |
Affected
|