Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Gentoo: 200308-03 Moderate: VMware Workstation Local Access Risk

gentoo
Calendar Grey August 25, 2003
Dist Gentoo Esm H88
Addressing a vulnerabilities within VMware Workstation that allows unintended local host access via modification of environmental variables.
By manipulating the VMware GSX Server and VMware Workstationenvironment variables, a program such as a shell session withroot privileges could be started when a virtual machine isl...

Summary


GENTOO LINUX SECURITY ANNOUNCEMENT 200308-03


- From advisory: "By manipulating the VMware GSX Server and VMware Workstation environment variables, a program such as a shell session with root privileges could be started when a virtual machine is launched. The user would then have full access to the host."

Read the full advisories at:


SOLUTION
It is recommended that all Gentoo Linux users who are running app-emulation/vmware-workstation upgrade to either vmware-workstation-3.2.1-2242 or vmware-workstation-4.0.1-5289 follows:
emerge sync emerge vmware-workstation- emerge clean
aliz@gentoo.org - GnuPG key is available at

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
important
Lowest
Low
Medium
High
Critical

PACKAGE : vmware-workstation
SUMMARY : local full host access
DATE : 2003-08-25 13:44 UTC
EXPLOIT : local
VERSIONS AFFECTED : <vmware-workstation-4.0.1-5289 =vmware-workstation-4.0.1-5289 >=vmware-workstation-3.2.1-2242
CVE : CAN-2003-0480 CAN-2003-0631

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Your message here