LWN.net Logo

vmware-workstation: vulnerability allows full host access

Package(s):vmware-workstation CVE #(s):CAN-2003-0480 CAN-2003-0631
Created:August 25, 2003 Updated:September 2, 2003
Description: According to this advisory vulnerabilities exist in VMware GSX Server 2.5.1 and earlier, and in VMware Workstation 4.0 and earlier releases. "By manipulating the VMware GSX Server and VMware Workstation environment variables, a program such as a shell session with root privileges could be started when a virtual machine is launched. The user would then have full access to the host."

See also CAN-2003-0480 and CAN-2003-0631

Alerts:
Gentoo 200308-03.1 2003-09-01
Gentoo 200308-03 2003-08-25

(Log in to post comments)

vmware-workstation: vulnerability allows full host access

Posted Aug 29, 2003 1:43 UTC (Fri) by wolfrider (guest, #3105) [Link]

--Thanks for the alert; I just downloaded the 2003-07-29 patched rev based on this article.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds