CVE-2010-0789
Summary
| CVE | CVE-2010-0789 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-03-02 18:30:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:L/AC:M/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fuse | Fuse | 1.9 | All | All | All |
| Application | Fuse | Fuse | 2.0 | pre0 | All | All |
| Application | Fuse | Fuse | 2.0 | pre1 | All | All |
| Application | Fuse | Fuse | 2.1 | All | All | All |
| Application | Fuse | Fuse | 2.2 | All | All | All |
| Application | Fuse | Fuse | 2.2.1 | All | All | All |
| Application | Fuse | Fuse | 2.3 | pre | All | All |
| Application | Fuse | Fuse | 2.3 | rc1 | All | All |
| Application | Fuse | Fuse | 2.3.0 | All | All | All |
| Application | Fuse | Fuse | 2.4.0 | All | All | All |
| Application | Fuse | Fuse | 2.4.1 | All | All | All |
| Application | Fuse | Fuse | 2.4.2 | All | All | All |
| Application | Fuse | Fuse | 2.5.0 | All | All | All |
| Application | Fuse | Fuse | 2.5.1 | All | All | All |
| Application | Fuse | Fuse | 2.5.2 | All | All | All |
| Application | Fuse | Fuse | 2.5.3 | All | All | All |
| Application | Fuse | Fuse | 2.6.0 | All | All | All |
| Application | Fuse | Fuse | 2.6.1 | All | All | All |
| Application | Fuse | Fuse | 2.6.3 | All | All | All |
| Application | Fuse | Fuse | 2.6.5 | All | All | All |
| Application | Fuse | Fuse | 2.7.0 | All | All | All |
| Application | Fuse | Fuse | 2.7.1 | All | All | All |
| Application | Fuse | Fuse | 2.7.2 | All | All | All |
| Application | Fuse | Fuse | 2.7.3 | All | All | All |
| Application | Fuse | Fuse | 2.7.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:013 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Bug 558833 – CVE-2009-3297 samba, fuse, ncpfs: Race condition by mount (mount.cifs, ncpmount) / umount (fusermount, ncpumount) operations [Fedora all] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Bug 532940 – CVE-2010-0788 ncpfs: Race condition by mount (ncpmount) / umount (ncpumount) operations | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| #567633 - race condition in fusermount - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| FUSE 'fusermount' Race Condition Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| USN-892-1: FUSE vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Debian update for fuse - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [SECURITY] Fedora 12 Update: fuse-2.8.1-4.fc12 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Debian -- Security Information -- DSA-1989-1 fuse | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Patch |
| Fedora update for fuse - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Filesystem in Userspace - Browse Files at SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Patch |
| Browse Filesystem in Userspace Files on SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:011 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| FUSE "fusermount" Race Condition Denial of Service - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:003 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [SECURITY] Fedora 11 Update: fuse-2.8.1-2.fc11 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Ubuntu update for fuse - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-04-07 | Vincent Danen | Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2010-0789 This issue affects Red Hat Enterprise Linux 5 because it ships fusermount suid root, however the impact of this flaw is minimized due to the fact that only members in group fuse may use it the executable is owned root:fuse and mode 4750. Red Hat Enterprise Linux 3 and 4 do not provide the fuse package. The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: http://www.redhat.com/security/updates/classification/ |
There are currently no legacy QID mappings associated with this CVE.