First published: Wed Nov 23 2022(Updated: )
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Open Vm Tools | =2009.03.18-154848 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-1142 is medium with a CVSS score of 6.7.
Local users can gain privileges by exploiting a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled.
The affected software for CVE-2009-1142 is VMware Open VM Tools version 2009.03.18-154848.
To fix CVE-2009-1142, update to a version of VMware Open VM Tools that is not affected by the vulnerability.
Yes, you can find references for CVE-2009-1142 [here](https://bugs.gentoo.org/264577) and [here](https://github.com/vmware/open-vm-tools/releases/tag/2009.03.18-154848).