Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 683134 - app-emulation/open-vm-tools: insecure handling of temp file
Summary: app-emulation/open-vm-tools: insecure handling of temp file
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL: https://github.com/vmware/open-vm-too...
Whiteboard: ~3 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2019-04-12 08:50 UTC by Agostino Sarubbo
Modified: 2019-04-12 17:53 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2019-04-12 08:50:41 UTC
From ${URL} :

/tmp/VMwareDnD is a staging directory used for DnD and CnP.  It should be
a regular directory, but malicious code or user may create the /tmp/VMwareDnD
as a symbolic link which points elsewhere on the system.  This may provide
user access to user B's files.

Do not set the permission of the root directory if the root directory
already exists and has the wrong permission.  The permission of the directory
must be 1777 if it is created by the VMToolsi.  If not, then the directory
has been created or modified by malicious code or user, so just cancel the
host to guest DnD or CnP operation.


@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Larry the Git Cow gentoo-dev 2019-04-12 17:53:22 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1014d67b6fef117cf70dbedd46149195b129fa00

commit 1014d67b6fef117cf70dbedd46149195b129fa00
Author:     Mike Gilbert <floppym@gentoo.org>
AuthorDate: 2019-04-12 17:51:58 +0000
Commit:     Mike Gilbert <floppym@gentoo.org>
CommitDate: 2019-04-12 17:52:48 +0000

    app-emulation/open-vm-tools: bump to 10.3.10
    
    Closes: https://bugs.gentoo.org/683134
    Package-Manager: Portage-2.3.62_p4, Repoman-2.3.12_p87
    Signed-off-by: Mike Gilbert <floppym@gentoo.org>

 app-emulation/open-vm-tools/Manifest                                  | 2 +-
 .../{open-vm-tools-10.3.5.ebuild => open-vm-tools-10.3.10.ebuild}     | 4 ++--
 2 files changed, 3 insertions(+), 3 deletions(-)