View previous topic :: View next topic |
Author |
Message |
GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sat Sep 29, 2012 2:26 pm Post subject: [ GLSA 201209-25 ] VMware Player, Server, Workstation: Multi |
|
|
Gentoo Linux Security Advisory
Title: VMware Player, Server, Workstation: Multiple vulnerabilities (GLSA 201209-25)
Severity: high
Exploitable: local, remote
Date: September 29, 2012
Bug(s): #213548, #224637, #236167, #245941, #265139, #282213, #297367, #335866, #385727
ID: 201209-25
Synopsis
Multiple vulnerabilities have been found in VMware Player, Server,
and Workstation, allowing remote and local attackers to conduct several
attacks, including privilege escalation, remote execution of arbitrary
code, and a Denial of Service.
Background
VMware Player, Server, and Workstation allow emulation of a complete PC
on a PC without the usual performance overhead of most emulators.
Affected Packages
Package: app-emulation/vmware-player
Vulnerable: <= 2.5.5.328052
Architectures: All supported architectures
Package: app-emulation/vmware-workstation
Vulnerable: <= 6.5.5.328052
Architectures: All supported architectures
Package: app-emulation/vmware-server
Vulnerable: <= 1.0.9.156507
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in VMware Player, Server,
and Workstation. Please review the CVE identifiers referenced below for
details.
Impact
Local users may be able to gain escalated privileges, cause a Denial of
Service, or gain sensitive information.
A remote attacker could entice a user to open a specially crafted file,
possibly resulting in the remote execution of arbitrary code, or a Denial
of Service. Remote attackers also may be able to spoof DNS traffic, read
arbitrary files, or inject arbitrary web script to the VMware Server
Console.
Furthermore, guest OS users may be able to execute arbitrary code on the
host OS, gain escalated privileges on the guest OS, or cause a Denial of
Service (crash the host OS).
Workaround
There is no known workaround at this time.
Resolution
Gentoo discontinued support for VMware Player. We recommend that users
unmerge VMware Player:
Code: | # emerge --unmerge "app-emulation/vmware-player"
| NOTE: Users could upgrade to
“>=app-emulation/vmware-player-3.1.5”, however these packages are
not currently stable.
Gentoo discontinued support for VMware Workstation. We recommend that
users unmerge VMware Workstation:
Code: | # emerge --unmerge "app-emulation/vmware-workstation"
| NOTE: Users could upgrade to
“>=app-emulation/vmware-workstation-7.1.5”, however these packages
are not currently stable.
Gentoo discontinued support for VMware Server. We recommend that users
unmerge VMware Server:
Code: | # emerge --unmerge "app-emulation/vmware-server"
|
References
CVE-2007-5269
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5503 ]
CVE-2007-5503
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5671 ]
CVE-2007-5671
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0967 ]
CVE-2008-0967
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1340 ]
CVE-2008-1340
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1361 ]
CVE-2008-1361
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1362 ]
CVE-2008-1362
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1363 ]
CVE-2008-1363
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1364 ]
CVE-2008-1364
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1392 ]
CVE-2008-1392
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1447 ]
CVE-2008-1447
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1806 ]
CVE-2008-1806
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1807 ]
CVE-2008-1807
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1808 ]
CVE-2008-1808
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2098 ]
CVE-2008-2098
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2100 ]
CVE-2008-2100
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2101 ]
CVE-2008-2101
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4915 ]
CVE-2008-4915
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4916 ]
CVE-2008-4916
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4917 ]
CVE-2008-4917
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0040 ]
CVE-2009-0040
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0909 ]
CVE-2009-0909
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0910 ]
CVE-2009-0910
[/url]
CVE-2009-1244
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2267 ]
CVE-2009-2267
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3707 ]
CVE-2009-3707
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3732 ]
CVE-2009-3732
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3733 ]
CVE-2009-3733
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4811 ]
CVE-2009-4811
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1137 ]
CVE-2010-1137
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1138 ]
CVE-2010-1138
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1139 ]
CVE-2010-1139
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1140 ]
CVE-2010-1140
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1141 ]
CVE-2010-1141
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1142 ]
CVE-2010-1142
[/url]
[url=http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1143 ]
CVE-2010-1143
[/url]
CVE-2011-3868
Last edited by GLSA on Fri Feb 07, 2014 4:31 am; edited 2 times in total |
|
Back to top |
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|