UNIX symbolic link following in open-vm-tools (Red Hat package) - CVE-2014-4199
Published: May 11, 2023
Vulnerability identifier: #VU76017
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-4199
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a symlink following issue. A local user can create a specially crafted symbolic link to a file in the "/tmp" folder and overwrite it, causing a denial of service condition.
Affected software
open-vm-tools (Red Hat package)
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for x86_64 - Extended Update Support
How to mitigate CVE-2014-4199
Install updates from vendor's website.
open-vm-tools (Red Hat package) - update to 9.10.2-4.el7