ALT-PU-2022-2597-2
Package open-vm-tools updated to version 12.1.0-alt1 for branch p10 in task 306078.
Closed vulnerabilities
BDU:2022-02316
Уязвимость набора утилит VMware Tools для операционных систем Windows, связанная с использованием ненадёжного пути поиска, позволяющая нарушителю выполнить произвольный код с системными привилегиями
BDU:2024-09868
Уязвимость компонента mount.vmhgfs набора модулей для продуктов VMware Open-vm-tools, связанная с неверным определением символических ссылок перед доступом к файлу, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2009-1143
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).
Modified: 2024-11-21
CVE-2011-1681
vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8.4.2-261024 and earlier attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to trigger corruption of this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
- [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110303 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110303 Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110307 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110315 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110401 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- 44904
- https://bugzilla.redhat.com/show_bug.cgi?id=688980
- vmware-vmwarehgfsmounter-sec-bypass(66699)
- openSUSE-SU-2011:0617
- [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- openSUSE-SU-2011:0617
- vmware-vmwarehgfsmounter-sec-bypass(66699)
- https://bugzilla.redhat.com/show_bug.cgi?id=688980
- 44904
- [oss-security] 20110401 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110315 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110307 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110303 Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110303 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
Modified: 2024-11-21
CVE-2022-22943
VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with system privileges in the Windows guest OS due to an uncontrolled search path element.