PT-2010-2854 · Vmware · Vmware Server+4

Published

2010-04-12

·

Updated

2013-05-15

·

CVE-2010-1138

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware Workstation versions 7.0 through 7.0.0 VMware Workstation version 6.5.x through 6.5.3 VMware Player versions 3.0 through 3.0.0 VMware Player version 2.5.x through 2.5.3 VMware ACE versions 2.6 through 2.6.0 and 2.5.x through 2.5.3 VMware Server version 2.x VMware Fusion versions 3.0 through 3.0.0 and 2.x through 2.0.6
Description The virtual networking stack allows remote attackers to obtain sensitive information from memory on the host OS by examining received network packets, related to interaction between the guest OS and the host vmware-vmx process.
Recommendations For VMware Workstation version 7.0, update to version 7.0.1 build 227600 or later. For VMware Workstation version 6.5.x, update to version 6.5.4 build 246459 or later. For VMware Player version 3.0, update to version 3.0.1 build 227600 or later. For VMware Player version 2.5.x, update to version 2.5.4 build 246459 or later. For VMware ACE versions 2.6 and 2.5.x, update to version 2.6.1 build 227600 or later and 2.5.4 build 246459 or later respectively. For VMware Server version 2.x, no specific fix is provided. For VMware Fusion versions 3.0 and 2.x, update to version 3.0.1 build 232708 or later and 2.0.7 build 246742 or later respectively.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1138

Affected Products

Vmware Ace
Vmware Fusion
Vmware Player
Vmware Server
Vmware Workstation