vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "2:10.2.0-3~ubuntu0.16.04.1", "binary_name": "open-vm-tools" }, { "binary_version": "2:10.2.0-3~ubuntu0.16.04.1", "binary_name": "open-vm-tools-dbgsym" }, { "binary_version": "2:10.2.0-3~ubuntu0.16.04.1", "binary_name": "open-vm-tools-desktop" }, { "binary_version": "2:10.2.0-3~ubuntu0.16.04.1", "binary_name": "open-vm-tools-desktop-dbgsym" }, { "binary_version": "2:10.2.0-3~ubuntu0.16.04.1", "binary_name": "open-vm-tools-dev" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "2:11.0.5-4ubuntu0.18.04.1", "binary_name": "open-vm-tools" }, { "binary_version": "2:11.0.5-4ubuntu0.18.04.1", "binary_name": "open-vm-tools-dbgsym" }, { "binary_version": "2:11.0.5-4ubuntu0.18.04.1", "binary_name": "open-vm-tools-desktop" }, { "binary_version": "2:11.0.5-4ubuntu0.18.04.1", "binary_name": "open-vm-tools-desktop-dbgsym" }, { "binary_version": "2:11.0.5-4ubuntu0.18.04.1", "binary_name": "open-vm-tools-dev" } ] }