Race Condition Affecting open-vm-tools package, versions <2:8.4.2+2011.08.21-471295-1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.06% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Race Condition vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-DEBIAN12-OPENVMTOOLS-1555266
  • published6 Jun 2011
  • disclosed6 Jun 2011

Introduced: 6 Jun 2011

CVE-2011-1787  (opens in a new tab)
CWE-362  (opens in a new tab)

How to fix?

Upgrade Debian:12 open-vm-tools to version 2:8.4.2+2011.08.21-471295-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream open-vm-tools package and not the open-vm-tools package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to gain privileges on the guest OS by mounting a filesystem on top of an arbitrary directory.

CVSS Scores

version 3.1