V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2018-10906
AST
MediumConfirmedExploit available

In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows no…

CVSS
5.3
Medium
EPSS
0.00
p15
Published
2018-01-01
Updated
2018-01-01
Description

In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.

Tags · CWE
CWE-285
CAPEC-1
CAPEC-5
CAPEC-13
CAPEC-17
CAPEC-39
CAPEC-45
CAPEC-51
CAPEC-59
CAPEC-60
CAPEC-76
CAPEC-77
CAPEC-87
CAPEC-104
CAPEC-127
CAPEC-402
CAPEC-647
CAPEC-668
Affected products
FuseFuseFuseFuseFuseFuseFuseFuseFuseFuseFuseFuseFuseFuseFuseFuseFuseFuseFuseFuse
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: L
Low (L)
Exploit indicators
EPSS
0.001 · p15
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-647 · CWE-285
└ via CAPEC-647 · CWE-285
└ via CAPEC-127 · CWE-285
└ via CAPEC-60 · CWE-285
└ via CAPEC-60 · CWE-285
└ via CAPEC-647 · CWE-285
└ via CAPEC-668 · CWE-285
└ via CAPEC-13 · CWE-285
Known exploits — Сканер-ВС
45106
exploitdb · https://www.exploit-db.com/exploits/45106
Enterprise
Affected software
ProductVendorStatus
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
fuseTracked
Source databases
AST
DEB
CVE
RED
UBU
Related vulnerabilities