- - - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200308-03
- - - ---------------------------------------------------------------------

          PACKAGE : vmware-workstation
          SUMMARY : local full host access
             DATE : 2003-08-25 13:44 UTC
          EXPLOIT : local
VERSIONS AFFECTED : <vmware-workstation-4.0.1-5289 =vmware-workstation-4.0.1-5289 >=vmware-workstation-3.2.1-2242
              CVE : CAN-2003-0480 CAN-2003-0631

- - - ---------------------------------------------------------------------

- From advisory:
"By manipulating the VMware GSX Server and VMware Workstation
environment variables, a program such as a shell session with
root privileges could be started when a virtual machine is
launched. The user would then have full access to the host."


Read the full advisories at: 



SOLUTION

It is recommended that all Gentoo Linux users who are running
app-emulation/vmware-workstation upgrade to either vmware-workstation-3.2.1-2242
or vmware-workstation-4.0.1-5289 follows:

emerge sync
emerge vmware-workstation-
emerge clean

- - - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at   
- - - ---------------------------------------------------------------------

Gentoo: vmware-server env variable vulnerability

By manipulating the VMware GSX Server and VMware Workstationenvironment variables, a program such as a shell session withroot privileges could be started when a virtual machine isl...

Summary


GENTOO LINUX SECURITY ANNOUNCEMENT 200308-03


- From advisory: "By manipulating the VMware GSX Server and VMware Workstation environment variables, a program such as a shell session with root privileges could be started when a virtual machine is launched. The user would then have full access to the host."

Read the full advisories at:


SOLUTION
It is recommended that all Gentoo Linux users who are running app-emulation/vmware-workstation upgrade to either vmware-workstation-3.2.1-2242 or vmware-workstation-4.0.1-5289 follows:
emerge sync emerge vmware-workstation- emerge clean
aliz@gentoo.org - GnuPG key is available at

Resolution

References

Availability

Concerns

Severity
PACKAGE : vmware-workstation
SUMMARY : local full host access
DATE : 2003-08-25 13:44 UTC
EXPLOIT : local
VERSIONS AFFECTED : <vmware-workstation-4.0.1-5289 =vmware-workstation-4.0.1-5289 >=vmware-workstation-3.2.1-2242
CVE : CAN-2003-0480 CAN-2003-0631

Synopsis

Background

Affected Packages

Impact

Workaround

Related News