VMware Products Multiple Vulnerabilities
RISK: Medium Risk
VMware Server
1. Various vulnerabilities are caused due to unspecified errors within certain ActiveX controls. These can be exploited to e.g. execute arbitrary code by tricking a user into visiting a malicious website.
2. An unspecified error when processing malformed requests exists within the ISAPI Extension. This can be exploited to cause a DoS by sending specially crafted requests to a vulnerable system.
3. An unspecified error related to "OpenProcess" can be exploited by malicious, local users on a host system to gain escalated privileges on the host system.
4. Some vulnerabilities in freetype can potentially be exploited by malicious people to compromise an application using the library.
VMware Workstation
1. Various vulnerabilities are caused due to unspecified errors within certain ActiveX controls. These can be exploited to e.g. execute arbitrary code by tricking a user into visiting a malicious website.
2. An unspecified error related to "OpenProcess" can be exploited by malicious, local users on a host system to gain escalated privileges on the host system.
This vulnerability affects VMware Workstation 5.x for Windows only.
3. Some vulnerabilities in freetype can potentially be exploited by malicious people to compromise an application using the library.
4. A vulnerability in cairo can potentially be exploited by malicious people to compromise an application using the library.
This vulnerability affects VMware Workstation 6.x for Linux only.
VMware Player
1. Various vulnerabilities are caused due to unspecified errors within certain ActiveX controls. These can be exploited to e.g. execute arbitrary code by tricking a user into visiting a malicious website.
2. An unspecified error related to "OpenProcess" can be exploited by malicious, local users on a host system to gain escalated privileges on the host system.
This vulnerability affects VMware Player 1.x for Linux only.
3. Some vulnerabilities in freetype can potentially be exploited by malicious people to compromise an application using the library.
4. A vulnerability in cairo can potentially be exploited by malicious people to compromise an application using the library.
VMware ACE
1. Various vulnerabilities are caused due to unspecified errors within certain ActiveX controls. These can be exploited to e.g. execute arbitrary code by tricking a user into visiting a malicious website.
2. An unspecified error related to "OpenProcess" can be exploited by malicious, local users on a host system to gain escalated privileges on the host system.
This vulnerability affects VMware ACE 1.x for Windows only.
VMware Fusion
1. Some vulnerabilities in freetype can potentially be exploited by malicious people to compromise an application using the library.
2. A vulnerability in cairo can potentially be exploited by malicious people to compromise an application using the library.
System / Technologies affected
- VMware Server 1.x
- VMware Workstation 5.x and 6.x
- VMware Player 1.x and 2.x
- VMware ACE 1.x and ACE 2.x
- VMware Fusion 1.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- VMware Server 1.x:
Update to version 1.0.7 build 108231 or later.
http://www.vmware.com/download/server/
- VMware Workstation 5.x:
Update to version 5.5.8 build 108000 or later.
http://www.vmware.com/download/ws/ws5.html - VMware Workstation 6.x:
Update to version 6.0.5 build 109488 or later.
http://www.vmware.com/download/ws/
- VMware Player 1.x:
Update to version 1.0.8 build 108000 or later.
http://www.vmware.com/download/player/ - VMware Player 2.x:
Update to version 2.0.5 build 109488 or later.
http://www.vmware.com/download/player/
- VMware ACE 1.x:
Update to version 1.0.7 build 108880 or later. - VMware ACE 2.x:
Update to version 2.0.5 build 109488 or later.
http://www.vmware.com/download/ace/
http://www.vmware.com/download/ace/
- VMware Fusion 1.x
There is no patch available for this vulnerability currently.
Vulnerability Identifier
- CVE-2007-5438
- CVE-2007-5503
- CVE-2008-1806
- CVE-2008-1807
- CVE-2008-1808
- CVE-2008-3691
- CVE-2008-3692
- CVE-2008-3693
- CVE-2008-3694
- CVE-2008-3695
- CVE-2008-3696
- CVE-2008-3697
- CVE-2008-3698
Source
Related Link
Share with