CVE-2015-3202
FUSE <2.9.3-15 - Local Privilege Escalation
Title source: llmDescription
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Tavis Ormandy · textlocallinux
https://www.exploit-db.com/exploits/37089
References (22)
... and 2 more
Scores
EPSS
0.0034
EPSS Percentile
56.0%
Classification
CWE
CWE-264
Status
draft
Affected Products (2)
debian/debian_linux
fuse_project/fuse
< 2.9.2
Timeline
Published
Jul 02, 2015
Tracked Since
Feb 18, 2026