Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.1.2.2015.238
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DLA-238-1)
Summary:The remote host is missing an update for the Debian 'fuse' package(s) announced via the DLA-238-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'fuse' package(s) announced via the DLA-238-1 advisory.

Vulnerability Insight:
Tavis Ormandy discovered that FUSE, a Filesystem in USErspace, does not scrub the environment before executing mount or umount with elevated privileges. A local user can take advantage of this flaw to overwrite arbitrary files and gain elevated privileges by accessing debugging features via the environment that would not normally be safe for unprivileged users.

For the old-oldstable distribution (squeeze-lts), this problem has been fixed in version 2.8.4-1.1+deb6u1.

We recommend that you upgrade your fuse packages.

Affected Software/OS:
'fuse' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
3.6

CVSS Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-3202
1032386
http://www.securitytracker.com/id/1032386
37089
https://www.exploit-db.com/exploits/37089/
74765
http://www.securityfocus.com/bid/74765
DSA-3266
http://www.debian.org/security/2015/dsa-3266
DSA-3268
http://www.debian.org/security/2015/dsa-3268
FEDORA-2015-8751
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159831.html
FEDORA-2015-8756
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159683.html
FEDORA-2015-8771
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159543.html
FEDORA-2015-8773
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159298.html
FEDORA-2015-8777
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160106.html
FEDORA-2015-8782
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160094.html
GLSA-201603-04
https://security.gentoo.org/glsa/201603-04
GLSA-201701-19
https://security.gentoo.org/glsa/201701-19
USN-2617-1
http://www.ubuntu.com/usn/USN-2617-1
USN-2617-2
http://www.ubuntu.com/usn/USN-2617-2
USN-2617-3
http://www.ubuntu.com/usn/USN-2617-3
[oss-security] 20150521 CVE-2015-3202 fuse privilege escalation
http://www.openwall.com/lists/oss-security/2015/05/21/9
http://packetstormsecurity.com/files/132021/Fuse-Local-Privilege-Escalation.html
https://gist.github.com/taviso/ecb70eb12d461dd85cba
https://twitter.com/taviso/status/601370527437967360
openSUSE-SU-2015:0997
http://lists.opensuse.org/opensuse-updates/2015-06/msg00005.html
openSUSE-SU-2015:1003
http://lists.opensuse.org/opensuse-updates/2015-06/msg00007.html
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.