VMware Open Virtual Machine Tools文件破坏漏洞

漏洞信息详情

VMware Open Virtual Machine Tools文件破坏漏洞

漏洞简介

VMware Open Virtual Machine Tools(又名open-vm-tools)8.4.2-261024及之前版本中的vmware-hgfsmounter尝试附加到/etc/mtab文件,而不是首先检查是否会影响资源的限制。本地用户可以借助带有极小RLIMIT_FSIZE值的进程,触发该文件的破坏。

漏洞公告

目前厂商还没有提供此漏洞的相关补丁或者升级程序,建议使用此软件的用户随时关注厂商的主页以获取最新版本:

http://open-vm-tools.sourceforge.net

参考网址

来源: bugzilla.redhat.com

链接:https://bugzilla.redhat.com/show_bug.cgi?id=688980

来源: MLIST

名称: [oss-security] 20110401 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/04/01/2

来源: MLIST

名称: [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/31/4

来源: MLIST

名称: [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/31/3

来源: MLIST

名称: [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/22/6

来源: MLIST

名称: [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/22/4

来源: MLIST

名称: [oss-security] 20110315 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/15/6

来源: MLIST

名称: [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/14/7

来源: MLIST

名称: [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/14/5

来源: MLIST

名称: [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/14/16

来源: MLIST

名称: [oss-security] 20110307 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/07/9

来源: MLIST

名称: [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/05/7

来源: MLIST

名称: [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/05/3

来源: MLIST

名称: [oss-security] 20110303 Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/04/9

来源: MLIST

名称: [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/04/12

来源: MLIST

名称: [oss-security] 20110303 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/04/11

来源: MLIST

名称: [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/04/10

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享