Link Following The advisory has been revoked - it doesn't affect any version of package open-vm-tools Open this link in a new tab
Threat Intelligence
EPSS
0.04% (6th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UBUNTU2004-OPENVMTOOLS-3146788
- published 24 Nov 2022
- disclosed 23 Nov 2022
Introduced: 23 Nov 2022
CVE-2009-1143 Open this link in a new tabAmendment
The Ubuntu
security team deemed this advisory irrelevant for Ubuntu:20.04
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream open-vm-tools
package and not the open-vm-tools
package as distributed by Ubuntu
.
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).