CVE-2008-1364
Summary
| CVE | CVE-2008-1364 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-03-20 00:44:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Unspecified vulnerability in the DHCP service in VMware Workstation 5.5.x before 5.5.6, VMware Player 1.0.x before 1.0.6, VMware ACE 1.0.x before 1.0.5, VMware Server 1.0.x before 1.0.5, and VMware Fusion 1.1.x before 1.1.1 allows attackers to cause a denial of service. |
Risk And Classification
Primary CVSS: v2.0 7.8 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:C
Problem Types: CWE-399 | NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Ace | 1.0 | All | All | All |
| Application | Vmware | Ace | 2.0 | All | All | All |
| Application | Vmware | Player | 1.0.2 | All | All | All |
| Application | Vmware | Player | 1.0.3 | All | All | All |
| Application | Vmware | Player | 1.0.4 | All | All | All |
| Application | Vmware | Player | 1.0.5 | All | All | All |
| Application | Vmware | Player | 2.0 | All | All | All |
| Application | Vmware | Player | 2.0.1 | All | All | All |
| Application | Vmware | Player | 2.0.2 | All | All | All |
| Application | Vmware | Server | 1.0.3 | All | All | All |
| Application | Vmware | Vmware Server | 1.0.2 | All | All | All |
| Application | Vmware | Vmware Server | 1.0.4 | All | All | All |
| Application | Vmware | Vmware Workstation | 5.5.5 | All | All | All |
| Application | Vmware | Vmware Workstation | 6.0.1 | All | All | All |
| Application | Vmware | Vmware Workstation | 6.0.2 | All | All | All |
| Application | Vmware | Workstation | 5.5 | All | All | All |
| Application | Vmware | Workstation | 5.5.3_build_34685 | All | All | All |
| Application | Vmware | Workstation | 5.5.3_build_42958 | All | All | All |
| Application | Vmware | Workstation | 5.5.4 | All | All | All |
| Application | Vmware | Workstation | 5.5.4_build_44386 | All | All | All |
| Application | Vmware | Workstation | 6.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| VMware Player Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch |
| [Security-announce] VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues | af854a3a-2127-422b-91ae-364da2661108 | lists.vmware.com | Patch |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| VMware Server Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch |
| VMSA-2008-0005.1 - VMware | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch |
| VMware Products Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - VMware Unspecified DHCP Bug Lets Users Deny Service | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| SecurityReason - VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Gentoo Linux Documentation -- VMware Player, Server, Workstation: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| VMware Workstation 5.5 Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| VMware Server 1.0.5 and Workstation 6.0.3 Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| VMware Fusion Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-06-03 | Mark J Cox | Not vulnerable. This issue did not affect the versions of dhcp as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5. |
There are currently no legacy QID mappings associated with this CVE.