DescriptionMurray McAllister
2014-11-20 01:55:04 UTC
The diagnostics archive created by vm-support was created in /tmp/ with world-readable permissions. A local attacker could possibly use this flaw to obtain sensitive information.
References:
http://seclists.org/fulldisclosure/2014/Aug/71
Comment 1Murray McAllister
2014-11-20 01:56:36 UTC
Created open-vm-tools tracking bugs for this issue:
Affects: fedora-all [bug 1165901]
Affects: epel-6 [bug 1165902]
Statement:
This issue affects the versions of open-vm-tools as shipped with Red Hat Enterprise Linux 7 and Red Hat CloudForms 4. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.