CVE-2009-1142: Medium severity red hat open vm tools desktop vulnerability
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1142?
The severity of CVE-2009-1142 is medium with a CVSS score of 6.7.
How can local users gain privileges in CVE-2009-1142?
Local users can gain privileges by exploiting a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled.
What is the affected software for CVE-2009-1142?
The affected software for CVE-2009-1142 is VMware Open VM Tools version 2009.03.18-154848.
How can I fix CVE-2009-1142?
To fix CVE-2009-1142, update to a version of VMware Open VM Tools that is not affected by the vulnerability.
Are there any references for CVE-2009-1142?
Yes, you can find references for CVE-2009-1142 [here](https://bugs.gentoo.org/264577) and [here](https://github.com/vmware/open-vm-tools/releases/tag/2009.03.18-154848).