PT-2008-3617 · Vmware · Vmware Player+6
Published
2008-06-05
·
Updated
2019-08-14
·
CVE-2008-2100
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware Workstation versions 5.x through 6.x
VMware Player versions 1.x through 2.x
VMware ACE version 2.x
VMware Server version 1.x
VMware Fusion version 1.x
VMware ESXi version 3.5
VMware ESX versions 3.0.1 through 3.5
VIX API versions 1.1.x before 1.1.4 build 93057
Description
The issue allows guest OS users to execute arbitrary code on the host OS via unspecified vectors due to multiple buffer overflows in the VIX API.
Recommendations
For VMware Workstation versions 5.x through 6.x, update to a version with VIX API 1.1.4 build 93057 or later.
For VMware Player versions 1.x through 2.x, update to a version with VIX API 1.1.4 build 93057 or later.
For VMware ACE version 2.x, update to a version with VIX API 1.1.4 build 93057 or later.
For VMware Server version 1.x, update to a version with VIX API 1.1.4 build 93057 or later.
For VMware Fusion version 1.x, update to a version with VIX API 1.1.4 build 93057 or later.
For VMware ESXi version 3.5, update to a version with VIX API 1.1.4 build 93057 or later.
For VMware ESX versions 3.0.1 through 3.5, update to a version with VIX API 1.1.4 build 93057 or later.
For VIX API versions 1.1.x before 1.1.4 build 93057, update to version 1.1.4 build 93057 or later.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vix Api
Vmware Ace
Vmware Esxi
Vmware Fusion
Vmware Player
Vmware Server
Vmware Workstation