J-Security Center

Title: VMware Symlink Vulnerability

Severity: LOW

Description:

VMware is software that runs multiple virtual computers on a single PC, at the same time, without partitioning or rebooting.

Certain versions of the VMWare for Linux product do not perform /tmp file sanity checking and create files in the /tmp directory which will follow symlinks. This may be used by a malicious user to overwrite any file (with log data) which falls within the write permissions of the user ID which VMWare excecutes as. Typically this is root. This attack will most likely result in a denial of service and not a root level compromise.

Affected Products:

  • VMWare VMWare 1.0.1
  • VMWare VMWare 1.0.2
  • VMWare VMWare 1.1.0
  • VMWare VMWare 1.1.1
  • VMWare VMWare 1.1.2

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.