VMware Products Directory Traversal Vulnerability
BID:36842
Info
VMware Products Directory Traversal Vulnerability
| Bugtraq ID: | 36842 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3733 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2009 12:00AM |
| Updated: | Oct 01 2012 07:10PM |
| Credit: | Justin Morehouse, Jason Kratzer |
| Vulnerable: |
VMWare Server 2.0.1 build 156745 VMWare Server 2.0.1 VMWare Server 1.0.9 build 156507 VMWare Server 1.0.9 VMWare Server 1.0.8 build 126538 VMWare Server 1.0.8 VMWare Server 1.0.7 build 108231 VMWare Server 1.0.7 VMWare Server 1.0.6 build 91891 VMWare Server 1.0.6 VMWare Server 1.0.5 Build 80187 VMWare Server 1.0.5 VMWare Server 1.0.4 VMWare Server 1.0.3 VMWare Server 1.0.2 VMWare Server 2.0 VMWare ESXi Server 3.5 ESXe350-20090440 VMWare ESXi Server 3.5 VMWare ESX Server 3.0.3 VMWare ESX Server 3.5 ESX350-200906407 VMWare ESX Server 3.5 ESX350-200904401 VMWare ESX Server 3.5 Gentoo Linux |
| Not Vulnerable: |
VMWare Server 2.0.2 Build 203138 VMWare Server 1.0.10 Build 203137 VMWare ESXi Server 4.0 VMWare ESXi Server 3.5 ESXe350-20091040 VMWare ESX Server 3.0.3 ESX303-200812406-BG VMWare ESX Server 4.0 VMWare ESX Server 3.5 ESX350-200910401 |
Discussion
VMware Products Directory Traversal Vulnerability
VMware products are prone to a directory-traversal vulnerability because they fail to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information from the host operating system that could aid in further attacks.
VMware products are prone to a directory-traversal vulnerability because they fail to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information from the host operating system that could aid in further attacks.
Exploit / POC
VMware Products Directory Traversal Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
VMware Products Directory Traversal Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
VMWare ESXi Server 3.5
VMWare Server 1.0.9
Solution:
The vendor has released an advisory and updates. Please see the references for details.
VMWare ESXi Server 3.5
-
VMWare ESXe350-200901401-O-SG.zip
http://download3.vmware.com/software/vi/ESXe350-200901401-O-SG.zip -
VMWare ESXe350-200901401-O-SG.zip
ESXi 3.5 patch ESXe350-200901401-I-SG (Directory Traversal)
http://download3.vmware.com/software/vi/ESXe350-200901401-O-SG.zip
VMWare Server 1.0.9
-
VMWare VMware-server-1.0.10-203137.i386.rpm
VMware Server for Linux rpm
http://download3.vmware.com/software/vmserver/VMware-server-1.0.10-203 137.i386.rpm -
VMWare VMware-server-1.0.10-203137.tar.gz
VMware Server for Linux
http://download3.vmware.com/software/vmserver/VMware-server-1.0.10-203 137.tar.gz -
VMWare VMware-server-installer-1.0.10-203137.exe
VMware Server for Windows 32-bit and 64-bit
http://download3.vmware.com/software/vmserver/VMware-server-installer- 1.0.10-203137.exe -
VMWare VMware-server-linux-client-1.0.10-203137.zip
VMware Server Linux client package
http://download3.vmware.com/software/vmserver/VMware-server-linux-clie nt-1.0.10-203137.zip -
VMWare VMware-server-win32-client-1.0.10-203137.zip
VMware Server Windows client package
http://download3.vmware.com/software/vmserver/VMware-server-win32-clie nt-1.0.10-203137.zip
References
VMware Products Directory Traversal Vulnerability
References:
References: