PT-2018-2964 · Vmware · Vmware Esxi+2

Publicado

2018-10-09

·

Atualizado

2019-10-03

·

CVE-2018-6977

CVSS v3.1

6.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions VMware ESXi versions 6.0 through 6.7 VMware Workstation versions 14.x through 15.x VMware Fusion versions 10.x through 11.x
Description The issue is related to an infinite loop in a 3D-rendering shader, which can cause a denial-of-service condition. This can make a virtual machine unresponsive and potentially affect other virtual machines on the host or the host itself. The vulnerability is associated with uncontrolled resource consumption in the 3D acceleration function of the hypervisors.
Recommendations For VMware ESXi versions 6.0 through 6.7, update to a version that includes a fix for the 3D-rendering shader issue. For VMware Workstation versions 14.x through 15.x, update to a version that includes a fix for the 3D-rendering shader issue. For VMware Fusion versions 10.x through 11.x, update to a version that includes a fix for the 3D-rendering shader issue. As a temporary workaround, consider disabling the 3D acceleration function in the affected virtual machines until a patch is available.

Correção

DoS

Infinite Loop

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02787
CVE-2018-6977

Produtos afetados

Vmware Esxi
Vmware Fusion
Vmware Workstation