CVE-2015-5191
published 2017-07-28CVE-2015-5191: VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of…
PriorityP424medium6.7CVSS 3.0
AVLACHPRLUIRSUCHIHAH
EPSS
0.33%
25.2th percentile
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | open-vm-tools | < open-vm-tools 2:10.1.5-5055683-5 (bookworm) | open-vm-tools 2:10.1.5-5055683-5 (bookworm) |
| vmware | open-vm-tools | >= 0 < 2:10.1.5-5055683-5 | 2:10.1.5-5055683-5 |
| vmware | open-vm-tools | >= 0 < 2:10.1.5-5055683-5 | 2:10.1.5-5055683-5 |
| vmware | open-vm-tools | >= 0 < 2:10.1.5-5055683-5 | 2:10.1.5-5055683-5 |
| vmware | open-vm-tools | >= 0 < 2:10.1.5-5055683-5 | 2:10.1.5-5055683-5 |
| vmware | tools | <= 10.0.8 | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vsphere | — | — |
CVSS provenance
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
osv6.7MEDIUM
vendor_debian6.7LOW
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Server and Tools updates resolve multiple security vulnerabilities
vendor_vmware·2017-07-27·CVSS 6.7
CVE-2015-5191 [MEDIUM] VMware vCenter Server and Tools updates resolve multiple security vulnerabilities
VMSA-2017-0013: VMware vCenter Server and Tools updates resolve multiple security vulnerabilities
a. Insecure library loading through LD_LIBRARY_PATH VMware vCenter Server contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation. Note: In order to exploit this issue an attacker should be able to trick the admin to execute wrapper scripts from a world writable directory. VMware would like to thank Thorsten Tüllmann, researcher at Karlsruhe Institute of Technology for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4
Red Hat
open-vm-tools: /tmp race conditions in the libDeployPkg component
vendor_redhat·2017-07-24·CVSS 6.7
CVE-2015-5191 [MEDIUM] open-vm-tools: /tmp race conditions in the libDeployPkg component
open-vm-tools: /tmp race conditions in the libDeployPkg component
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Package: open-vm-tools (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2015-5191: open-vm-tools - VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg...
vendor_debian·2015·CVSS 6.7
CVE-2015-5191 [MEDIUM] CVE-2015-5191: open-vm-tools - VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg...
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Scope: local
bookworm: resolved (fixed in 2:10.1.5-5055683-5)
bullseye: resolved (fixed in 2:10.1.5-5055683-5)
forky: resolved (fixed in 2:10.1.5-5055683-5)
sid: resolved (fixed in 2:10.1.5-5055683-5)
trixie: resolved (fixed in 2:10.1.5-5055683-5)
GHSA
GHSA-4vr2-36wr-v82r: VMware Tools prior to 10
ghsa_unreviewed·2022-05-17
CVE-2015-5191 [MEDIUM] CWE-362 GHSA-4vr2-36wr-v82r: VMware Tools prior to 10
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
OSV
CVE-2015-5191: VMware Tools prior to 10
osv·2017-07-28·CVSS 6.7
CVE-2015-5191 [MEDIUM] CVE-2015-5191: VMware Tools prior to 10
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5191 open-vm-tools: /tmp race conditions in the libDeployPkg component [fedora-all]
bugzilla·2017-07-25·CVSS 6.7
CVE-2015-5191 [MEDIUM] CVE-2015-5191 open-vm-tools: /tmp race conditions in the libDeployPkg component [fedora-all]
CVE-2015-5191 open-vm-tools: /tmp race conditions in the libDeployPkg component [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2015-5191 open-vm-tools: /tmp race conditions in the libDeployPkg component
bugzilla·2015-08-14·CVSS 6.7
CVE-2015-5191 [MEDIUM] CVE-2015-5191 open-vm-tools: /tmp race conditions in the libDeployPkg component
CVE-2015-5191 open-vm-tools: /tmp race conditions in the libDeployPkg component
It was discovered that open-vm-tools has multiple /tmp race conditions in the libDeployPkg component, allowing an unprivileged local user in a guest to cause a denial of service through file system manipulation, or, possibly, increase privileges.
Acknowledgements:
This issue was discovered by Florian Weimer of Red Hat Product Security.
Discussion:
Created open-vm-tools tracking bugs for this issue:
Affects: fedora-all [bug 1474701]
---
References:
http://seclists.org/oss-sec/2017/q3/209
Upstream patches:
9.10.x – https://github.com/vmware/open-vm-tools/commit/c1304ce8bfd9c0c33999e496bf7049d5c3d45821
10.0.x - https://github.com/vmware/open-vm-tools/commit/b3068b04880eda4ca3e13f2d34fb8ce336ad1a4f
10.1.
2017-07-28
Published