ALT-PU-2024-2252-3
Package open-vm-tools updated to version 12.3.5-alt1 for branch c10f2 in task 340574.
Closed vulnerabilities
BDU:2023-07234
Уязвимость набора утилит VMware Tools для операционных систем Windows, связанная с недостатками процедуры авторизации, позволяющая нарушителю повысить свои привилегии
BDU:2024-09868
Уязвимость компонента mount.vmhgfs набора модулей для продуктов VMware Open-vm-tools, связанная с неверным определением символических ссылок перед доступом к файлу, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2009-1143
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).
Modified: 2024-11-21
CVE-2011-1681
vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8.4.2-261024 and earlier attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to trigger corruption of this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
- [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110303 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110303 Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110307 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110315 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110401 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- 44904
- https://bugzilla.redhat.com/show_bug.cgi?id=688980
- vmware-vmwarehgfsmounter-sec-bypass(66699)
- openSUSE-SU-2011:0617
- [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- openSUSE-SU-2011:0617
- vmware-vmwarehgfsmounter-sec-bypass(66699)
- https://bugzilla.redhat.com/show_bug.cgi?id=688980
- 44904
- [oss-security] 20110401 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110315 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110307 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110303 Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
- [oss-security] 20110303 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
Modified: 2025-03-06
CVE-2023-34058
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
- http://www.openwall.com/lists/oss-security/2023/10/27/1
- http://www.openwall.com/lists/oss-security/2023/10/27/1
- https://lists.debian.org/debian-lts-announce/2023/11/msg00002.html
- https://lists.debian.org/debian-lts-announce/2023/11/msg00002.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G7G77Z76CQPGUF7VHRA6O3UFCMPPR4O2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G7G77Z76CQPGUF7VHRA6O3UFCMPPR4O2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MQUOFQL2SNNNMKROQ3TZQY4HEYMNOIBW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MQUOFQL2SNNNMKROQ3TZQY4HEYMNOIBW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLTKVTRKQW2GD2274H3UOW6XU4E62GSK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLTKVTRKQW2GD2274H3UOW6XU4E62GSK/
- https://www.debian.org/security/2023/dsa-5543
- https://www.debian.org/security/2023/dsa-5543
- https://www.vmware.com/security/advisories/VMSA-2023-0024.html
- https://www.vmware.com/security/advisories/VMSA-2023-0024.html
Modified: 2025-03-06
CVE-2023-34059
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.
- http://www.openwall.com/lists/oss-security/2023/10/27/2
- http://www.openwall.com/lists/oss-security/2023/10/27/2
- http://www.openwall.com/lists/oss-security/2023/10/27/3
- http://www.openwall.com/lists/oss-security/2023/10/27/3
- http://www.openwall.com/lists/oss-security/2023/11/26/1
- http://www.openwall.com/lists/oss-security/2023/11/26/1
- http://www.openwall.com/lists/oss-security/2023/11/27/1
- http://www.openwall.com/lists/oss-security/2023/11/27/1
- https://lists.debian.org/debian-lts-announce/2023/11/msg00002.html
- https://lists.debian.org/debian-lts-announce/2023/11/msg00002.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G7G77Z76CQPGUF7VHRA6O3UFCMPPR4O2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G7G77Z76CQPGUF7VHRA6O3UFCMPPR4O2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MQUOFQL2SNNNMKROQ3TZQY4HEYMNOIBW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MQUOFQL2SNNNMKROQ3TZQY4HEYMNOIBW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLTKVTRKQW2GD2274H3UOW6XU4E62GSK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLTKVTRKQW2GD2274H3UOW6XU4E62GSK/
- https://www.debian.org/security/2023/dsa-5543
- https://www.debian.org/security/2023/dsa-5543
- https://www.openwall.com/lists/oss-security/2023/10/27/3
- https://www.vmware.com/security/advisories/VMSA-2023-0024.html
- https://www.vmware.com/security/advisories/VMSA-2023-0024.html