Secunia Logo  


Secunia PSI WorldMap
 
VMware Products Multiple Vulnerabilities
Secunia Advisory: SA25079
Release Date: 2007-05-01
Last Update: 2007-05-21
Popularity: 13,204 views

Critical:
Moderately critical
Impact: Security Bypass
DoS
Where: Local system
Solution Status: Vendor Patch

OS:VMware ESX Server 2.x
VMware ESX Server 3.x

Software:VMware ACE 1.x
VMware Player 1.x
VMware Server 1.x
VMware Workstation 5.x

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 2 of 3)[ 1 ] [ 2 ] [ 3 ]

Solution:
Update to the latest versions or apply patches.

* VMware Workstation 5.5.4, Build 44386:
http://www.vmware.com/download/ws/

* VMware Server 1.0.3, Build 44356:
http://www.vmware.com/download/server/

* VMware Player 1.0.4, Build 44386:
http://www.vmware.com/download/player/

* VMware ACE 1.03, Build 44385:
http://www.vmware.com/download/ace/

* VMware ESX Server 3.0.1:

ESX-6856573
http://www.vmware.com/support/vi3/doc/esx-6856573-patch.html
md5sum 16bb030929bb005fe26c09f637cb9cd8

ESX-6431040
http://www.vmware.com/support/vi3/doc/esx-6431040-patch.html
md5sum ef6bc745b3d556e0736fd39b8ddc8087

ESX-6704314
http://www.vmware.com/support/vi3/doc/esx-6704314-patch.html
md5sum 2470567517a64726b1c5929c59ed6134

ESX-5095559
http://www.vmware.com/support/vi3/doc/esx-5095559-patch.html
md5sum bcded4127598c22d47f06ab03366d2f8

* VMware ESX Server 3.0.0:

ESX-3496682
http://www.vmware.com/support/vi3/doc/esx-3496682-patch.html
md5sum 929c6830a4cdc939b0b2a35e83e3b1ac

ESX-5754280
http://www.vmware.com/support/vi3/doc/esx-5754280-patch.html
md5sum 82b3c7e18dd1422f30c4aa9e477c6a27

ESX-1256636
http://www.vmware.com/support/vi3/doc/esx-1256636-patch.html
md5sum e7f0b1920bd2a609d1c3b18249717f2c

ESX-7104553
http://www.vmware.com/support/vi3/doc/esx-7104553-patch.html
md5sum 81c4f33331a4cbc565c1d9a44b1ea4fc

* VMware ESX Server 2.5.4:
http://www.vmware.com/support/esx25/doc/esx-254-200704-patch.html
md5sum ef4d601c130c7a08176827252bc01152

* VMware ESX Server 2.5.3:
http://www.vmware.com/support/esx25/doc/esx-253-200704-patch.html
md5sum be048c744cdcd71b3da92098efe06f08

* VMware ESX Server 2.1.3:
http://www.vmware.com/support/esx21/doc/esx-213-200704-patch.html
md5sum 2dfc6aca32c77d673b0f7a1295ad7609

* VMware ESX Server 2.0.2:
http://www.vmware.com/support/esx2/doc/esx-202-200704-patch.html
md5sum 0e997bd53d94dff2d9452e5679bd1b3c

Provided and/or discovered by:
1) Tavis Ormandy, Google
2) Sungard Ixsecurity
3) Ruben Santamarta, Reversemode
4) Ken Johnson
5) Greg MacManus, iDefense Labs

Changelog:
2007-05-03: Added additional affected products and fix information. Updated vendor links.
2007-05-08: Updated advisory based on new information from vendor. Added additional links as well as affected product and fix information.
2007-05-21: Added additional link, affected product, and fix information.

Original Advisory:
VMware:
http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554
http://www.vmware.com/support/server/doc/releasenotes_server.html#resolved
http://www.vmware.com/support/player/doc/releasenotes_player.html#104
http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/054161.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063436.html

3) Reversemode:
http://www.reversemode.com/index.php?...;Itemid=2&func=fileinfo&id=49

5) iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=521

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

26th Nov, 2009
New advisories: 15
New vulnerabilities: 37
Updated advisories: 49

Moderately // 277 views
SugarCRM Multiple Vulnerabilities
Moderately // 230 views
Debian update for poppler
Moderately // 230 views
Debian update for php5
Less // 269 views
HP-UX update for OpenSSL

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Solaris 8 LDAP Client Configuration Cache Daemon Denial of Service // 24 views
2. Sun Java JDK / JRE Multiple Vulnerabilities // 24 views
3. Kaspersky Anti-Virus 2010 klavemu.kdl Denial of Service Vulnerability // 22 views
4. Sun Solaris LDAP Client Configuration Cache Daemon Denial of Service // 21 views
5. Serenity "MplayInputFile()" M3U Playlist Buffer Overflow // 21 views
6. IBM DB2 "DASAUTO" Command Privilege Escalation // 21 views
7. Sun Solaris BIND DNS Cache Poisoning Vulnerability // 19 views
8. HP-UX update for OpenSSL // 19 views
9. Ingate Firewall and SIParator Multiple Vulnerabilities // 19 views
10. SugarCRM Multiple Vulnerabilities // 18 views