Bug 1603048 (CVE-2018-6969) - CVE-2018-6969 open-vm-tools: Out-of-bounds read in HGFS allows for information disclosure or potential privilege escalation
Summary: CVE-2018-6969 open-vm-tools: Out-of-bounds read in HGFS allows for informatio...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2018-6969
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1603049 1603050 1603051
Blocks: 1603053
TreeView+ depends on / blocked
 
Reported: 2018-07-19 03:59 UTC by Sam Fowler
Modified: 2021-12-10 16:41 UTC (History)
15 users (show)

Fixed In Version: open-vm-tools 10.3.0
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-07-20 18:36:59 UTC
Embargoed:


Attachments (Terms of Use)

Description Sam Fowler 2018-07-19 03:59:03 UTC
VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may lead to information disclosure or may allow attackers to escalate their privileges on the guest VMs. In order to be able to exploit this issue, file sharing must be enabled.


External Reference:

https://www.vmware.com/security/advisories/VMSA-2018-0017.html

Comment 1 Sam Fowler 2018-07-19 03:59:50 UTC
Created open-vm-tools tracking bugs for this issue:

Affects: epel-6 [bug 1603050]
Affects: fedora-all [bug 1603049]

Comment 3 Ravindra Kumar 2018-07-19 22:30:58 UTC
This advisory does not affect open-vm-tools, because it is about a Windows specific issue. I'm copying a note from https://www.vmware.com/security/advisories/VMSA-2018-0017.html here:

===================
This issue only affects Windows VMs running on VMware Workstation or Fusion.
===================

Comment 4 Jeff Nelson 2018-07-20 03:01:10 UTC
Ravindra,

That not is not visible to me when I visit https://www.vmware.com/security/advisories/VMSA-2018-0017.html. Can you confirm it's still present? The only note I see is about file sharing:

---

1. Summary

VMware Tools update addresses an out-of-bounds read vulnerability

2. Relevant Products

 VMware Tools

3. Problem Description

VMware Tools HGFS out-of-bounds read vulnerability

VMware Tools contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may lead to information disclosure or may allow attackers to escalate their privileges on the guest VMs.

Note: In order to be able to exploit this issue, file sharing must be enabled.

VMware would like to thank Anurudh for reporting this issue to us.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2018-6969 to this issue.

Column 5 of the following table...

---

If this really just affects Windows guests running on VMware Workstation or Fusion, I think we can close the CVE as NOTABUG.

Comment 5 Ravindra Kumar 2018-07-20 06:41:04 UTC
(In reply to Jeff Nelson from comment #4)
> That not is not visible to me when I visit
> https://www.vmware.com/security/advisories/VMSA-2018-0017.html. Can you
> confirm it's still present?

May be you are seeing old page. There was an update made today with following changelog entry:

----------
VMSA-2018-0017.1 2018-07-17
Updated Security Advisory to clarify the affected products.
----------

If you are not seeing the changelog entry above, you are probably looking at the stale page and need to refresh your browser somehow.

> If this really just affects Windows guests running on VMware Workstation or
> Fusion, I think we can close the CVE as NOTABUG.

I'm part of the same development team and I can confirm this with confidence that it does not apply to non-Windows guests.

Comment 6 Rick Barry 2018-07-20 15:08:23 UTC
Based on Ravindra's statement in comment 5, this is a Windows-only issue (it does mention that in the table he refers to in https://www.vmware.com/security/advisories/VMSA-2018-0017.html). 

Engineering's opinion is that this bug and its dependent bugs should be closed as NOTABUG or WONTFIX.

Product Security Team, if you agree that we can close the dependent bugs do you have a preference on the resolution status: WONTFIX versus NOTABUG?

Comment 7 Scott Gayou 2018-07-20 18:35:36 UTC
Clearing needinfo. NOTABUG as per VMware developer.


Note You need to log in before you can comment on or make changes to this bug.