Access Restriction Bypass Affecting open-vm-tools package, versions <2:8.4.2+2011.08.21-471295-1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.06% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN12-OPENVMTOOLS-1555383
  • published6 Jun 2011
  • disclosed6 Jun 2011

Introduced: 6 Jun 2011

CVE-2011-2145  (opens in a new tab)
CWE-264  (opens in a new tab)

How to fix?

Upgrade Debian:12 open-vm-tools to version 2:8.4.2+2011.08.21-471295-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream open-vm-tools package and not the open-vm-tools package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1, when a Solaris or FreeBSD guest OS is used, allows guest OS users to modify arbitrary guest OS files via unspecified vectors, related to a "procedural error."

CVSS Scores

version 3.1