VMWare Workstation Local Format String Vulnerability
BID:11737
Info
VMWare Workstation Local Format String Vulnerability
| Bugtraq ID: | 11737 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 23 2004 12:00AM |
| Updated: | Nov 23 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Reed Arvin <[email protected]>. |
| Vulnerable: |
VMWare Workstation 4.5.2 |
| Not Vulnerable: | |
Discussion
VMWare Workstation Local Format String Vulnerability
A potential format string handling vulnerability is reported to exist in the VMWare workstation executable. It is reported that the affected executable does not correctly handle format specifier characters that are passed to the application as a command line argument. Although unconfirmed, under circumstances where the affected VMWare application is installed with setuid privileges, this failure to handle format strings may facilitate privilege escalation.
A potential format string handling vulnerability is reported to exist in the VMWare workstation executable. It is reported that the affected executable does not correctly handle format specifier characters that are passed to the application as a command line argument. Although unconfirmed, under circumstances where the affected VMWare application is installed with setuid privileges, this failure to handle format strings may facilitate privilege escalation.
Exploit / POC
VMWare Workstation Local Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
VMWare Workstation Local Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.