CVE-2009-1143
Publication date 23 November 2022
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).
Status
Package | Ubuntu Release | Status |
---|---|---|
open-vm-tools | ||
22.04 LTS jammy |
Not affected
|
|
20.04 LTS focal | Ignored | |
18.04 LTS bionic | Ignored | |
16.04 LTS xenial | Ignored | |
14.04 LTS trusty | Ignored |
Notes
mdeslaur
mount.vmhgfs not suid root in Debian and Ubuntu, negligible security impact. Upstream commit removes vmhgfs in favour of hgfs-fuse. Since this has no security impact on Ubuntu, and there is no upstream fix for the issue, we will not be fixing this in stable releases.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.0 · High |
Attack vector | Local |
Attack complexity | High |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |