VMware Player and Workstation 'vmware-authd' Remote Denial of Service Vulnerability
BID:36630
Info
VMware Player and Workstation 'vmware-authd' Remote Denial of Service Vulnerability
| Bugtraq ID: | 36630 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-3707 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 07 2009 12:00AM |
| Updated: | Apr 13 2010 06:22PM |
| Credit: | shinnai |
| Vulnerable: |
VMWare Workstation 6.5.3 VMWare Workstation 6.5.2 VMWare Workstation 6.5.1 VMWare Workstation 6.5 build 118166 VMWare Workstation 7.0 VMWare Workstation 6.5.3 build 185404 VMWare Workstation 6.5.2 build 156735 VMWare Player 2.5.4 VMWare Player 2.5.3 VMWare Player 2.5.2 build 156735 VMWare Player 2.5.2 VMWare Player 2.5.1 VMWare Player 2.5 build 118166 VMWare Player 3.0 VMWare Player 2.5.3 build 185404 VMWare ACE 2.5.3 Build 185404 VMWare ACE 2.5.2 build 156735 VMWare ACE 2.5.2 VMWare ACE 2.5.1 VMWare ACE 2.5 build 118166 VMWare ACE 2.6 |
| Not Vulnerable: |
VMWare Workstation 7.0.1 build 227600 VMWare Workstation 6.5.4 build 246459 VMWare Player 3.0.1 build 227600 VMWare Player 2.5.4 build 246459 VMWare ACE 2.6.1 build 227600 VMWare ACE 2.5.4 build 246459 |
Discussion
VMware Player and Workstation 'vmware-authd' Remote Denial of Service Vulnerability
VMware Player and Workstation are prone to a remote denial-of-service vulnerability because the applications fail to perform adequate validation checks on user-supplied input.
An attacker can exploit this issue to crash the 'vmware-authd' process, denying service to legitimate users.
NOTE: This issue was also covered in BID 39345 (VMware Hosted Products VMSA-2010-0007 Multiple Remote and Local Vulnerabilities); this BID is being retained to properly document the issue.
VMware Player and Workstation are prone to a remote denial-of-service vulnerability because the applications fail to perform adequate validation checks on user-supplied input.
An attacker can exploit this issue to crash the 'vmware-authd' process, denying service to legitimate users.
NOTE: This issue was also covered in BID 39345 (VMware Hosted Products VMSA-2010-0007 Multiple Remote and Local Vulnerabilities); this BID is being retained to properly document the issue.
Exploit / POC
VMware Player and Workstation 'vmware-authd' Remote Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
VMware Player and Workstation 'vmware-authd' Remote Denial of Service Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
VMware Player and Workstation 'vmware-authd' Remote Denial of Service Vulnerability
References:
References: