PT-2009-2861 · Vmware · Vmware Player+4
Laurent Gaffiã©
·
Publicado
2009-01-20
·
Atualizado
2017-10-19
·
CVE-2009-0177
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
VMware Workstation versions 6.5.1 and earlier
VMware Player versions 2.5.1 and earlier
VMware ACE versions 2.5.1 and earlier
VMware Server versions prior to 2.0.1 build 156745
VMware Fusion versions prior to 2.0.2 build 147997
Description
The issue allows remote attackers to cause a denial of service, resulting in a daemon crash. This can be achieved by sending a long
USER or PASS command.Recommendations
For VMware Workstation versions 6.5.1 and earlier, update to a version later than 6.5.1.
For VMware Player versions 2.5.1 and earlier, update to a version later than 2.5.1.
For VMware ACE versions 2.5.1 and earlier, update to a version later than 2.5.1.
For VMware Server versions prior to 2.0.1 build 156745, update to version 2.0.1 build 156745 or later.
For VMware Fusion versions prior to 2.0.2 build 147997, update to version 2.0.2 build 147997 or later.
Exploit
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vmware Ace
Vmware Fusion
Vmware Player
Vmware Server
Vmware Workstation