fusermount in FUSE before 2.4.1, if installed setuid root, allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters.
http://www.vupen.com/english/advisories/2005/2529
http://www.securityfocus.com/bid/15529
http://www.mandriva.com/security/advisories?name=MDKSA-2005:216
http://www.gentoo.org/security/en/glsa/glsa-200511-17.xml