Bug 1253689 (CVE-2015-5191) - CVE-2015-5191 open-vm-tools: /tmp race conditions in the libDeployPkg component
Summary: CVE-2015-5191 open-vm-tools: /tmp race conditions in the libDeployPkg component
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2015-5191
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=low,public=20170724,reported=2...
Depends On: 1253690 1253691 1253698 1474701
Blocks: 1253700
TreeView+ depends on / blocked
 
Reported: 2015-08-14 13:09 UTC by Florian Weimer
Modified: 2019-06-08 20:42 UTC (History)
9 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-06-08 02:43:06 UTC


Attachments (Terms of Use)

Description Florian Weimer 2015-08-14 13:09:57 UTC
It was discovered that open-vm-tools has multiple /tmp race conditions in the libDeployPkg component, allowing an unprivileged local user in a guest to cause a denial of service through file system manipulation, or, possibly, increase privileges.

Acknowledgements:

This issue was discovered by Florian Weimer of Red Hat Product Security.

Comment 11 Andrej Nemec 2017-07-25 08:12:14 UTC
Created open-vm-tools tracking bugs for this issue:

Affects: fedora-all [bug 1474701]


Note You need to log in before you can comment on or make changes to this bug.