VMware Products Multiple Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in various VMware products, which could be exploited by local or remote attackers to bypass security restrictions, cause a denial of service or compromise a vulnerable system.
1. Due to an input validation error in the "HGFS.sys" driver, which could allow local attackers to execute arbitrary code on the guest system.
2. Due to an untrusted library path error in "vmware-authd", which could be exploited by local unprivileged attackers to execute arbitrary code on the Linux host system.
3. Due to an error within the processing of "Content-Length" headers in the openwsman management service, which may allow unprivileged users to gain root privileges.
4. Due to buffer overflow errors in the VIX Application Programming Interface (API), which may result in code execution on the host system or on the service console in ESX Server from the guest operating system.
Impact
- Denial of Service
- Remote Code Execution
- Security Restriction Bypass
System / Technologies affected
- VMware Workstation
- VMware Player
- VMware ACE
- VMware Fusion
- VMware Server
- VMware VIX API
- VMware ESX
- VMware ESXi
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to VMware Workstation version 5.5.7 :
http://www.vmware.com/download/ws/ - Upgrade to VMware Player version 2.0.4 or 1.0.7 :
http://www.vmware.com/download/player/ - Upgrade to VMware ACE version 2.0.4 or 1.0.6 :
http://www.vmware.com/download/ace/ - Upgrade to VMware Server version 1.0.6 :
http://www.vmware.com/download/server/ - Upgrade to VMware Fusion version 1.1.3 :
http://www.vmware.com/download/fusion/ - Upgrade to VMware VIX version 1.1.4 :
http://www.vmware.com/support/developer/vix-api/ - Apply patches for VMware ESX :
http://www.vmware.com/security/advisories/VMSA-2008-0009.html
Vulnerability Identifier
- CVE-2006-1721
- CVE-2007-4772
- CVE-2007-5378
- CVE-2007-5671
- CVE-2008-0062
- CVE-2008-0063
- CVE-2008-0553
- CVE-2008-0888
- CVE-2008-0948
- CVE-2008-0967
- CVE-2008-2097
- CVE-2008-2100
Source
Related Link
Share with