CVE-2009-3707
Summary
| CVE | CVE-2009-3707 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-10-16 16:30:00 UTC |
| Updated | 2013-05-15 03:01:00 UTC |
| Description | VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\xFF sequence in the USER and PASS commands, related to a "format string DoS" issue. NOTE: some of these details are obtained from third party information. |
Risk And Classification
Problem Types: CWE-134
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Ace | 2.5.0 | All | All | All |
| Application | Vmware | Ace | 2.5.1 | All | All | All |
| Application | Vmware | Ace | 2.5.2 | All | All | All |
| Application | Vmware | Ace | 2.5.3 | All | All | All |
| Application | Vmware | Ace | 2.5.4 | All | All | All |
| Application | Vmware | Ace | 2.6 | All | All | All |
| Application | Vmware | Ace | 2.6.1 | All | All | All |
| Application | Vmware | Ace | 2.5.0 | All | All | All |
| Application | Vmware | Ace | 2.5.1 | All | All | All |
| Application | Vmware | Ace | 2.5.2 | All | All | All |
| Application | Vmware | Ace | 2.5.3 | All | All | All |
| Application | Vmware | Ace | 2.5.4 | All | All | All |
| Application | Vmware | Ace | 2.6 | All | All | All |
| Application | Vmware | Ace | 2.6.1 | All | All | All |
| Application | Vmware | Player | 2.5 | All | All | All |
| Application | Vmware | Player | 2.5.1 | All | All | All |
| Application | Vmware | Player | 2.5.2 | All | All | All |
| Application | Vmware | Player | 2.5.3 | All | All | All |
| Application | Vmware | Player | 2.5.4 | All | All | All |
| Application | Vmware | Player | 3.0 | All | All | All |
| Application | Vmware | Player | 3.0.1 | All | All | All |
| Application | Vmware | Player | 2.5 | All | All | All |
| Application | Vmware | Player | 2.5.1 | All | All | All |
| Application | Vmware | Player | 2.5.2 | All | All | All |
| Application | Vmware | Player | 2.5.3 | All | All | All |
| Application | Vmware | Player | 2.5.4 | All | All | All |
| Application | Vmware | Player | 3.0 | All | All | All |
| Application | Vmware | Player | 3.0.1 | All | All | All |
| Application | Vmware | Server | 2.0.0 | All | All | All |
| Application | Vmware | Server | 2.0.1 | All | All | All |
| Application | Vmware | Server | 2.0.2 | All | All | All |
| Application | Vmware | Server | 2.0.0 | All | All | All |
| Application | Vmware | Server | 2.0.1 | All | All | All |
| Application | Vmware | Server | 2.0.2 | All | All | All |
| Application | Vmware | Workstation | 6.5.0 | All | All | All |
| Application | Vmware | Workstation | 6.5.1 | All | All | All |
| Application | Vmware | Workstation | 6.5.2 | All | All | All |
| Application | Vmware | Workstation | 6.5.3 | All | All | All |
| Application | Vmware | Workstation | 6.5.4 | All | All | All |
| Application | Vmware | Workstation | 7.0 | All | All | All |
| Application | Vmware | Workstation | 7.0.1 | All | All | All |
| Application | Vmware | Workstation | 6.5.0 | All | All | All |
| Application | Vmware | Workstation | 6.5.1 | All | All | All |
| Application | Vmware | Workstation | 6.5.2 | All | All | All |
| Application | Vmware | Workstation | 6.5.3 | All | All | All |
| Application | Vmware | Workstation | 6.5.4 | All | All | All |
| Application | Vmware | Workstation | 7.0 | All | All | All |
| Application | Vmware | Workstation | 7.0.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware Server Multiple Vulnerabilities - Advisories - Community | SECUNIA | secunia.com | |
| VMware Products Multiple Vulnerabilities - Advisories - Community | SECUNIA | secunia.com | |
| Gentoo Linux Documentation -- VMware Player, Server, Workstation: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| [Security-announce] VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues | MLIST | lists.vmware.com | |
| www.shinnai.net/xplits/TXT_JtYUv6C6j5b6Bw6iIkF4.html | MISC | www.shinnai.net | Exploit |
| About Secunia Research | Flexera | SECUNIA | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - VMware Authorization Service Lets Remote Users Deny Service | SECTRACK | securitytracker.com | |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | BUGTRAQ | archives.neohapsis.com | |
| www.shinnai.net/exploits/abFwcLOuFqmD20yqhYpQ.txt | MISC | www.shinnai.net | |
| www.shinnai.net/index.php | MISC | www.shinnai.net | |
| VMware Player and Workstation 'vmware-authd' Remote Denial of Service Vulnerability | BID | www.securityfocus.com | |
| VMSA-2010-0007.1 | CONFIRM | www.vmware.com | |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | FULLDISC | archives.neohapsis.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.