CVE-2009-1143 PUBLISHED

An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).

EPSS 0.03% · 8.4th percentile

Risk Scores

EPSS Score
0.03%
8.4th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSopen-vm-tools2:10.2.0-3~ubuntu0.16.04.1+esm1, 2:10.2.0-3~ubuntu0.16.04.1+esm2, 2:10.2.0-3~ubuntu0.16.04.1+esm3
Ubuntu:Pro:20.04:LTSopen-vm-tools2:11.0.1-2, 2:10.3.10-3ubuntu1, 0
Ubuntu:Pro:14.04:LTSopen-vm-tools2:9.4.0-1280544-5ubuntu4, 2013.09.16-1328054-0ubuntu1, 2013.09.16-1328054-0ubuntu2
Ubuntu:Pro:18.04:LTSopen-vm-tools2:11.0.5-4ubuntu0.18.04.3+esm3, 2:11.0.5-4ubuntu0.18.04.3+esm4, 2:11.0.5-4ubuntu0.18.04.3+esm2

Timeline

References

Open in Interactive Console →