CVE Database
/

CVE-2018-10906

Back to search

CVE-2018-10906

Published: Jul 24, 2018

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.0

5.3

MEDIUM

Description

In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.

VendorProductVersions

[UNKNOWN]

fuse

affected
fuse 2.9.8
affected
fuse 3.2.5

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

Low

References

DSA-4257
vendor-advisory
x_refsource_DEBIAN
45106
exploit
x_refsource_EXPLOIT-DB
RHSA-2018:3324
vendor-advisory
x_refsource_REDHAT
FEDORA-2019-dd00364b71
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-31722b8f33
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-fd54b80806
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now