Vulnerability CVE-2013-1662


Published: 2013-08-23   Modified: 2013-08-24

Description:
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library function.

See advisories in our WLB2 database:
Topic
Author
Date
High
VMWare Setuid vmware-mount Unsafe popen(3)
egypt
29.08.2013

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:L/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.9/10
10/10
3.4/10
Exploit range
Attack complexity
Authentication
Local
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Vmware -> Player 
Vmware -> Workstation 

 References:
http://www.vmware.com/security/advisories/VMSA-2013-0010.html
http://blog.cmpxchg8b.com/2013/08/security-debianisms.html

Copyright 2024, cxsecurity.com

 

Back to Top