Vulnerability CVE-2008-4917


Published: 2008-12-08   Modified: 2012-02-12

Description:
Unspecified vulnerability in VMware Workstation 5.5.8 and earlier, and 6.0.5 and earlier 6.x versions; VMware Player 1.0.8 and earlier, and 2.0.5 and earlier 2.x versions; VMware Server 1.0.9 and earlier; VMware ESXi 3.5; and VMware ESX 3.0.2 through 3.5 allows guest OS users to have an unknown impact by sending the virtual hardware a request that triggers an arbitrary physical-memory write operation, leading to memory corruption.

Type:

CWE-399

(Resource Management Errors)

Vendor: Vmware
Product: Workstation 
Version:
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1_build_55017
6.0.1
6.0
5.5.8
5.5.7
5.5.6
5.5.5_build_56455
5.5.5
5.5.4_build_44386
5.5.4
5.5.3_build_42958
5.5.3_build_34685
5.5.3
5.5.2
5.5.1_build_19175
5.5.1
5.5.0_build_13124
5.5
Product: Vmware workstation 
Version:
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
5.5.7
5.5.6
5.5.5
5.5.4
5.5.3
5.5.2
5.5.1
5.5.0
5.0
Product: ESX 
Version:
3.5
3.0.3
3.0.2
Product: ESXI 
Version: 3.5;
Product: Player 
Version:
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1_build_55017
2.0.1
2.0
1.0.8
1.0.7
1.0.6
1.0.5_build_56455
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
1.0
Product: Server 
Version:
1.0.9
1.0.8
1.0.7
1.0.6
1.0.5
1.0.4_build_56528
1.0.4
1.0.3
1.0.2
1.0.1_build_29996
1.0.1
1.0

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://kb.vmware.com/kb/1006980
http://kb.vmware.com/kb/1006986
http://security.gentoo.org/glsa/glsa-201209-25.xml
http://securitytracker.com/id?1021300
http://securitytracker.com/id?1021301
http://www.securityfocus.com/archive/1/498863/100/0/threaded
http://www.securityfocus.com/archive/1/498886/100/0/threaded
http://www.securityfocus.com/bid/32597
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6246

Related CVE
CVE-2018-6982
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may lead to an information leak from host to guest.
CVE-2018-6981
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware Workstation 15, VMware Workstation 14.1.3 or below, VMware Fusion 11, VMware Fusion 10.1.3 or below co...
CVE-2018-11077
'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerabili...
CVE-2018-11076
Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may b...
CVE-2018-11067
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection vulnerabilit...
CVE-2018-11066
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain a Remote Code Execution vulnerab...
CVE-2018-6977
VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user ...
CVE-2018-6970
VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1) contain an out-of-bounds read vulnerability in the Message Framework library. Successfully exploiting this issue may allow a less...

Copyright 2019, cxsecurity.com

 

Back to Top