Total vulnerabilities in the database
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
Software | From | Fixed in |
---|---|---|
debian / debian_linux | 8.0 | 8.0.x |
fuse_project / fuse | - | 2.9.2.x |