- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200308-03.1
- - ---------------------------------------------------------------------

� � � � � PACKAGE : vmware
� � � � � SUMMARY : insecure symbolic links
� � � � � � �DATE : 2003-09-01 13:42 UTC
� � � � � EXPLOIT : local
VERSIONS AFFECTED : =vmware-workstation-4.0.2.5592
� � � � � � � CVE :

- - ---------------------------------------------------------------------

The previous GLSA 200308-03 was wrong when it stated that
vmware-workstation-4.0.1-5289 would fix the problems described in the
advisory.

SOLUTION

It is recommended that all Gentoo Linux users who are running
app-emulation/vmware-workstation-4.x upgrade to
vmware-workstation-4.0.1-5289 as follows

emerge sync
emerge \=app-emulation/vmware-workstation/vmware-workstation-4.0.2.5592
emerge clean

- - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at   
- - ---------------------------------------------------------------------

Gentoo: vmware Insecure symlink vulnerability

The previous GLSA 200308-03 was wrong when it stated thatvmware-workstation-4.0.1-5289 would fix the problems described in theadvisory.

Summary


- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200308-03.1
- - ---------------------------------------------------------------------

- - ---------------------------------------------------------------------
The previous GLSA 200308-03 was wrong when it stated that vmware-workstation-4.0.1-5289 would fix the problems described in the advisory.
SOLUTION
It is recommended that all Gentoo Linux users who are running app-emulation/vmware-workstation-4.x upgrade to vmware-workstation-4.0.1-5289 as follows
emerge sync emerge \=app-emulation/vmware-workstation/vmware-workstation-4.0.2.5592 emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - - ---------------------------------------------------------------------

Resolution

References

Availability

Concerns

Severity
� � � � � PACKAGE : vmware
� � � � � SUMMARY : insecure symbolic links
� � � � � � �DATE : 2003-09-01 13:42 UTC
� � � � � EXPLOIT : local
VERSIONS AFFECTED : =vmware-workstation-4.0.2.5592
� � � � � � � CVE :

Synopsis

Background

Affected Packages

Impact

Workaround

Related News