Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 421269 (CVE-2012-3288) - <app-emulation/vmware-workstation-{7.1.6,8.0.4}, <app-emulation/vmware-player-{3.1.6,4.0.4}: Checkpoint file memory corruption and remote device DoS (CVE-2012-{3288,3289})
Summary: <app-emulation/vmware-workstation-{7.1.6,8.0.4}, <app-emulation/vmware-player...
Status: RESOLVED FIXED
Alias: CVE-2012-3288
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-06-15 19:41 UTC by GLSAMaker/CVETool Bot
Modified: 2012-06-19 01:37 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2012-06-15 19:41:41 UTC
CVE-2012-3289 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3289):
  VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware
  ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow remote attackers
  to cause a denial of service (guest OS crash) via crafted traffic from a
  remote virtual device.

CVE-2012-3288 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3288):
  VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x
  before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware
  ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow user-assisted
  remote attackers to execute arbitrary code on the host OS or cause a denial
  of service (memory corruption) on the host OS via a crafted Checkpoint file.
Comment 1 Vadim Kuznetsov (RETIRED) gentoo-dev 2012-06-17 13:16:25 UTC
VMware Workstation 7.1.6 and 8.0.4, VMware Player 3.1.6 and 4.0.4 are in the tree.
Older versions are removed.
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2012-06-19 01:37:52 UTC
Thank you, Vadim. Closing noglsa for ~arch only package.