Vulnerability Description
fusermount in FUSE before 2.4.1, if installed setuid root, allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Miklos Szeredi | Fuse | 2.2 |
References
- http://secunia.com/advisories/17691
- http://secunia.com/advisories/17695
- http://www.gentoo.org/security/en/glsa/glsa-200511-17.xmlPatchVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:216
- http://www.securityfocus.com/bid/15529Patch
- http://www.vupen.com/english/advisories/2005/2529
- http://secunia.com/advisories/17691
- http://secunia.com/advisories/17695
- http://www.gentoo.org/security/en/glsa/glsa-200511-17.xmlPatchVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:216
- http://www.securityfocus.com/bid/15529Patch
- http://www.vupen.com/english/advisories/2005/2529
FAQ
What is CVE-2005-3531?
CVE-2005-3531 is a vulnerability with a CVSS score of 2.1 (LOW). fusermount in FUSE before 2.4.1, if installed setuid root, allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain ...
How severe is CVE-2005-3531?
CVE-2005-3531 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-3531?
Check the references section above for vendor advisories and patch information. Affected products include: Miklos Szeredi Fuse.