CVE-2009-0910
Summary
| CVE | CVE-2009-0910 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-04-06 15:30:00 UTC |
| Updated | 2017-09-29 01:34:00 UTC |
| Description | Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-436. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Ace | 2.5.1 | All | All | All |
| Application | Vmware | Ace | 2.5.1 | All | All | All |
| Application | Vmware | Player | 2.5.1 | All | All | All |
| Application | Vmware | Player | 2.5.1 | All | All | All |
| Application | Vmware | Server | 2.0 | All | All | All |
| Application | Vmware | Server | 2.0 | All | All | All |
| Application | Vmware | Workstation | 6.5.1 | All | All | All |
| Application | Vmware | Workstation | 6.5.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware Hosted Products VMSA-2009-0005 Multiple Remote Vulnerabilities | BID | www.securityfocus.com | Exploit |
| Gentoo Linux Documentation -- VMware Player, Server, Workstation: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| [Security-announce] VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues | MLIST | lists.vmware.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| VMware Heap Overflows in VNnc Codec Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | |
| VMSA-2009-0005 | CONFIRM | www.vmware.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Full Disclosure: VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues | FULLDISC | seclists.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.