CVE Reference: CVE-2008-0967

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-0967

Description:
Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a library path option in a configuration file.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/42878

ST
  1020198

SREASON
  http://securityreason.com/securityalert/3922

SAID
  Secunia Advisory: SA30556

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4768
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5583

IDEFENSE
  http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=713

GENTOO
  http://security.gentoo.org/glsa/glsa-201209-25.xml

CONFIRM
  http://www.vmware.com/security/advisories/VMSA-2008-0009.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/493080/100/0/threaded

BID
  29557


Return to the previous page.