UNIX symbolic link following in open-vm-tools (Red Hat package) - CVE-2014-4199

 

UNIX symbolic link following in open-vm-tools (Red Hat package) - CVE-2014-4199

Published: May 11, 2023


Vulnerability identifier: #VU76017
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-4199
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a symlink following issue. A local user can create a specially crafted symbolic link to a file in the "/tmp" folder and overwrite it, causing a denial of service condition.


Affected software

open-vm-tools (Red Hat package)
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for x86_64 - Extended Update Support

How to mitigate CVE-2014-4199

Install updates from vendor's website.

open-vm-tools (Red Hat package) - update to 9.10.2-4.el7

External References

Related Security Bulletins