PT-2010-2854 · Vmware · Vmware Server+4
Published
2010-04-12
·
Updated
2013-05-15
·
CVE-2010-1138
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
VMware Workstation versions 7.0 through 7.0.0
VMware Workstation version 6.5.x through 6.5.3
VMware Player versions 3.0 through 3.0.0
VMware Player version 2.5.x through 2.5.3
VMware ACE versions 2.6 through 2.6.0 and 2.5.x through 2.5.3
VMware Server version 2.x
VMware Fusion versions 3.0 through 3.0.0 and 2.x through 2.0.6
Description
The virtual networking stack allows remote attackers to obtain sensitive information from memory on the host OS by examining received network packets, related to interaction between the guest OS and the host vmware-vmx process.
Recommendations
For VMware Workstation version 7.0, update to version 7.0.1 build 227600 or later.
For VMware Workstation version 6.5.x, update to version 6.5.4 build 246459 or later.
For VMware Player version 3.0, update to version 3.0.1 build 227600 or later.
For VMware Player version 2.5.x, update to version 2.5.4 build 246459 or later.
For VMware ACE versions 2.6 and 2.5.x, update to version 2.6.1 build 227600 or later and 2.5.4 build 246459 or later respectively.
For VMware Server version 2.x, no specific fix is provided.
For VMware Fusion versions 3.0 and 2.x, update to version 3.0.1 build 232708 or later and 2.0.7 build 246742 or later respectively.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Ace
Vmware Fusion
Vmware Player
Vmware Server
Vmware Workstation