<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>224637</bug_id>
          
          <creation_ts>2008-06-02 17:25 0000</creation_ts>
          <short_desc>VMware Multiple vulnerabilities (CVE-2007-5671,CVE-2008-{0967,2098,2100})</short_desc>
          <delta_ts>2008-07-24 00:28:02 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>ASSIGNED</bug_status>
          
          <bug_file_loc>http://www.vmware.com/security/advisories/VMSA-2008-0008.html</bug_file_loc>
          <status_whiteboard>B2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>craig@gentoo.org</cc>
    
    <cc>jesse@boldandbusted.com</cc>
    
    <cc>kronenpj@kronenpj.dyndns.org</cc>
    
    <cc>micheleschi@gmail.com</cc>
    
    <cc>reillyeon@qotw.net</cc>
    
    <cc>s.hase@gmx.org</cc>
    
    <cc>vmware@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-02 17:25:11 0000</bug_when>
            <thetext>CVE-2008-2098 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2098):
  Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in
  VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4
  build 93057, VMware ACE 2 before 2.0.2 build 93057, and VMware Fusion before
  1.1.2 build 87978, when folder sharing is used, allows guest OS users to
  execute arbitrary code on the host OS via unspecified vectors.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-02 17:28:34 0000</bug_when>
            <thetext>We need these fixed versions:
Workstation 6.x Linux 6.0.4 build 93057
Player 2.x Linux 2.0.4 build 93057

All others (incl. stable) are not affected.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>craig@gentoo.org</who>
            <bug_when>2008-06-04 17:23:44 0000</bug_when>
            <thetext>The advisory VMSA-2008-0009 says:
Workstation   6.x       Linux    not affected
Player        2.x       Linux    not affected</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>craig@gentoo.org</who>
            <bug_when>2008-06-04 17:31:21 0000</bug_when>
            <thetext>Oh damn, wait, that was just one of them, sorry!
Also see http://bugs.gentoo.org/show_bug.cgi?id=224861</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ikelos@gentoo.org</who>
            <bug_when>2008-06-04 22:08:29 0000</bug_when>
            <thetext>Ok,

vmware-player and vmware-workstation have been bumped in the overlay.  I haven&apos;t added them to the tree yet, because I&apos;m still working out some kinks in the new modules.  For some reason, vmware decided to bump the module version number, which creates headaches (and a new package vmware-modules-1.0.0.20) for us.  I have yet to investigate what vmware-server-1.0.6 needs, but I&apos;ll try and work on that in the next few days.

If I get hit by a bus or people think I&apos;m taking too long or anything, the vmware overlay&apos;s where to look for the bumps for this bug...  5:)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ikelos@gentoo.org</who>
            <bug_when>2008-06-04 22:09:13 0000</bug_when>
            <thetext>*** Bug 224861 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-05 07:22:25 0000</bug_when>
            <thetext>Mike, thanks for preparing testing ebuilds in the overlay. I hope they are recent enough to also take care of the issues mentioned here:
http://www.vmware.com/security/advisories/VMSA-2008-0009.html
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-05 07:22:39 0000</bug_when>
            <thetext>*** Bug 224927 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ikelos@gentoo.org</who>
            <bug_when>2008-06-05 08:22:14 0000</bug_when>
            <thetext>We&apos;ve got testing ebuilds for:

vmware-player-2.0.4.93057
vmware-workstation-6.0.4.93057

Sounds like we still need:

vmware-server-1.0.6.91891
vmware-player-1.0.7.91707
vmware-workstation-5.5.7.91707

Hopefully I&apos;ll get those ready this weekend...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>craig@gentoo.org</who>
            <bug_when>2008-06-05 09:51:01 0000</bug_when>
            <thetext>That would be cool. Let me know, if you need someone for testing.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2008-06-06 01:44:02 0000</bug_when>
            <thetext>*** Bug 225051 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2008-06-08 14:47:16 0000</bug_when>
            <thetext>*** Bug 225343 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ikelos@gentoo.org</who>
            <bug_when>2008-06-08 15:08:46 0000</bug_when>
            <thetext>Ok,

It turns out the following were easy to bump, and are now in the vmware overlay:

vmware-server-1.0.6.91891
vmware-player-1.0.7.91707
vmware-workstation-5.5.7.91707

They&apos;ll probably be quite easy to push into the tree, and should happen in the next couple of days.  The other two should remain in testing in the overlay for the next week.  We need as many eyes as possible testing the following versions to ensure that the new modules are all working ok...

vmware-player-2.0.4.93057
vmware-workstation-6.0.4.93057

Thanks  5:)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>micheleschi@gmail.com</who>
            <bug_when>2008-06-08 15:15:00 0000</bug_when>
            <thetext>sorry, but where&apos;s the overlay ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ikelos@gentoo.org</who>
            <bug_when>2008-06-08 19:34:05 0000</bug_when>
            <thetext>You can test it out using layman (emerge layman; layman -a vmware), or you can get it manually from http://overlays.gentoo.org/proj/vmware/

Hope that helps...  5:)  </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>micheleschi@gmail.com</who>
            <bug_when>2008-06-08 20:05:19 0000</bug_when>
            <thetext>ah...

I just discover e new world of gentoo....

Thank&apos;s</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>craig@gentoo.org</who>
            <bug_when>2008-06-08 21:00:43 0000</bug_when>
            <thetext>Thanks Mike!
Unfortunately, I can&apos;t see vmware-server-1.0.6.91891 in the vmware layout, I sync&apos;ed right now. Are you sure it&apos;s in there?!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>reillyeon@qotw.net</who>
            <bug_when>2008-06-08 21:49:02 0000</bug_when>
            <thetext>Tested vmware-workstation-6.0.4.93057 and vmware-modules-1.0.0.20 on amd64 with gentoo-sources-2.6.25-r4.  Everything working as expected.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>micheleschi@gmail.com</who>
            <bug_when>2008-06-08 22:08:47 0000</bug_when>
            <thetext>also for me, 

uname -a
Linux uzzmaster 2.6.25-gentoo-r4 #1 SMP PREEMPT Thu Jun 5 01:02:02 CEST 2008 x86_64 Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz GenuineIntel GNU/Linux
uzzmaster ~ # emerge vmware-modules vmware-workstation -pv

These are the packages that would be merged, in order:

Calculating dependencies... done!
[ebuild   R   ] app-emulation/vmware-modules-1.0.0.20  0 kB [1]
[ebuild   Rf  ] app-emulation/vmware-workstation-6.0.4.93057  0 kB [1]

Total: 2 packages (2 reinstalls), Size of downloads: 0 kB
Fetch Restriction: 1 package
Portage tree and overlays:
 [0] /usr/portage
 [1] /usr/local/portage
uzzmaster ~ # 
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>craig@gentoo.org</who>
            <bug_when>2008-06-10 14:58:52 0000</bug_when>
            <thetext>Ouch. I just forgot to change the PORTAGE_OVERLAY. :(
1.0.6 works without any problems here.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ikelos@gentoo.org</who>
            <bug_when>2008-06-14 23:35:46 0000</bug_when>
            <thetext>Ok,

The tree now contains:

vmware-player-1.0.7.91707
vmware-player-2.0.4.93057
vmware-server-1.0.6.91891
vmware-server-console-1.0.6.91891
vmware-workstation-5.5.7.91707
vmware-workstation-6.0.4.93057

Please let me know if there are any problems or any further work needed for this bug...  5:)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ikelos@gentoo.org</who>
            <bug_when>2008-06-14 23:39:32 0000</bug_when>
            <thetext>Sorry, also whilst it occurs to me, vmware-workstation-4.5.3 was published in 2005 and was the last update for the 4.5 series (it&apos;s downloadable but no longer updated by vmware).

Given the two or three recent security bugs with vmware packages, it should really be masked for removal due to lack of upstream support.  Unfortunately, I have the feeling there may still be people using it (because it&apos;s a pay for product and they may not want to pay to upgrade).

So what&apos;s the recommendation for it?  Mask it or not?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2008-06-15 08:58:12 0000</bug_when>
            <thetext>(In reply to comment #21)
&gt; So what&apos;s the recommendation for it?  Mask it or not?

Should have been done so,long, long ago.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-15 09:27:39 0000</bug_when>
            <thetext>VMware Workstation 4.5.3.19414-r7 is already marked vulnerable by several GLSAs, and since it is not slotted, users are therefore advised to upgrade. I agree it should also be removed from the tree in a timely fashion, either by just &quot;cvs rm&quot; or prior mask, at your choice.

As for VMware 5.5, it will reach end of life at Nov. 09 2008. We should be prepared to have the 6.0 branch stable prior to that, so people can start upgrading their installations rather sooner than later.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-15 09:52:06 0000</bug_when>
            <thetext>Arches, please test and mark stable:
=app-emulation/vmware-workstation-5.5.7.91707
=app-emulation/vmware-player-1.0.7.91707
=app-emulation/vmware-server-1.0.6.91891
=app-emulation/vmware-server-console-1.0.6.91891

Target keywords : &quot;amd64 release x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2008-06-16 21:52:28 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rich0@gentoo.org</who>
            <bug_when>2008-06-17 23:54:49 0000</bug_when>
            <thetext>amd64 stable for the vmware-server and vmware-server-console packages (alas - I don&apos;t have a workstation license to test)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-06-22 11:43:01 0000</bug_when>
            <thetext>amd64 stable, all arches done.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jesse@boldandbusted.com</who>
            <bug_when>2008-07-02 21:04:59 0000</bug_when>
            <thetext>Re Comment #25: Ah, sorry, but is 5.5.7.91707 really marked stable? Just sync&apos;d, and it is still masked ~x86. Thanks!

In ../vmware-workstation/vmware-workstation-5.5.7.91707.ebuild:

[...]
KEYWORDS=&quot;-* amd64 ~x86&quot;
[...]</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hoffie@gentoo.org</who>
            <bug_when>2008-07-02 21:31:33 0000</bug_when>
            <thetext>(In reply to comment #28)
&gt; Re Comment #25: Ah, sorry, but is 5.5.7.91707 really marked stable? Just
&gt; sync&apos;d, and it is still masked ~x86. Thanks!
&gt; 
&gt; In ../vmware-workstation/vmware-workstation-5.5.7.91707.ebuild:
&gt; 
&gt; [...]
&gt; KEYWORDS=&quot;-* amd64 ~x86&quot;
&gt; [...]
Looks like you are right, I&apos;m seeing the same in my (up-to-date) cvs checkout. Re-CC&apos;ing x86, adjusting whiteboard.

$ grep KEYW vmware-workstation/vmware-workstation-5.5.7.91707.ebuild vmware-player/vmware-player-1.0.7.91707.ebuild vmware-server/vmware-server-1.0.6.91891.ebuild vmware-server-console/vmware-server-console-1.0.6.91891.ebuild 
vmware-workstation/vmware-workstation-5.5.7.91707.ebuild:KEYWORDS=&quot;-* amd64 ~x86&quot;
vmware-player/vmware-player-1.0.7.91707.ebuild:KEYWORDS=&quot;-* amd64 ~x86&quot;
vmware-server/vmware-server-1.0.6.91891.ebuild:KEYWORDS=&quot;-* amd64 ~x86&quot;
vmware-server-console/vmware-server-console-1.0.6.91891.ebuild:KEYWORDS=&quot;-* amd64 ~x86&quot;

Don&apos;t see a ChangeLog entry either, so apparently something has gone wrong when committing.

x86, please re-check. :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2008-07-03 12:33:57 0000</bug_when>
            <thetext>This must have slipped me...fixed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hoffie@gentoo.org</who>
            <bug_when>2008-07-03 13:40:53 0000</bug_when>
            <thetext>(In reply to comment #30)
&gt; This must have slipped me...fixed
vmware-workstation looks right now, all the other listed packages are still ~x86, at least in my cvs checkout at the time of writing this. x86 back to the fun... =)

$ grep KEYW vmware-workstation/vmware-workstation-5.5.7.91707.ebuild \
    vmware-server-console/vmware-server-console-1.0.6.91891.ebuild \
    vmware-player/vmware-player-1.0.7.91707.ebuild \
    vmware-server/vmware-server-1.0.6.91891.ebuild \
    vmware-server-console/vmware-server-console-1.0.6.91891.ebuild
vmware-workstation/vmware-workstation-5.5.7.91707.ebuild:KEYWORDS=&quot;-* amd64 x86&quot;
vmware-server-console/vmware-server-console-1.0.6.91891.ebuild:KEYWORDS=&quot;-* amd64 ~x86&quot;
vmware-player/vmware-player-1.0.7.91707.ebuild:KEYWORDS=&quot;-* amd64 ~x86&quot;
vmware-server/vmware-server-1.0.6.91891.ebuild:KEYWORDS=&quot;-* amd64 ~x86&quot;
vmware-server-console/vmware-server-console-1.0.6.91891.ebuild:KEYWORDS=&quot;-* amd64 ~x86&quot;

Jesse Adelman, thanks for reporting this initially, btw. ;)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2008-07-03 13:53:56 0000</bug_when>
            <thetext>Could you please stop hassling my machine with your negative karma?  You mess
up all my commits!  x86 done...I hope. :)</thetext>
          </long_desc>
      
    </bug>

</bugzilla>