VMware Symlink Vulnerability

BID:943

Info

VMware Symlink Vulnerability

Bugtraq ID: 943
Class: Origin Validation Error
CVE:
Remote: No
Local: Yes
Published: Jan 21 2000 12:00AM
Updated: Jan 21 2000 12:00AM
Credit: This vulnerability was detailed in a W00W00 advisory and posted to the Bugtraq mailing list by harikiri <[email protected]> on Mon, 24 Jan 2000.
Vulnerable: VMWare VMWare 1.1.2
VMWare VMWare 1.1.1
VMWare VMWare 1.1
VMWare VMWare 1.0.2
VMWare VMWare 1.0.1
Not Vulnerable:

Discussion

VMware Symlink Vulnerability

VMware is software that runs multiple virtual computers on a single PC, at the same time, without partitioning or rebooting.

Certain versions of the VMWare for Linux product do not perform /tmp file sanity checking and create files in the /tmp directory which will follow symlinks. This may be used by a malicious user to overwrite any file (with log data) which falls within the write permissions of the user ID which VMWare excecutes as. Typically this is root. This attack will most likely result in a denial of service and not a root level compromise.

Solution / Fix

VMware Symlink Vulnerability

Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].

VMWare does however let allow you to set the location of your temporary directory for it's file creation via the $TMPDIR environment variable. Therefore you may wish to set your $TMPDIR variable to something with more stringent permissions, such as a sub-directory off your own home directory ($HOME).

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report