Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 224861
Alias:
Product:
Component:
Status: RESOLVED
Resolution: DUPLICATE of bug 224637
Assigned To: Gentoo VMWare Bug Squashers <vmware@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Stefan Behte <craig@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 224861 depends on: Show dependency tree
Bug 224861 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-06-04 09:28 0000
Hi, it's available since 5/29/08 and as there was no ticket open, I was so
outrageous and created this bugtracker entry ;)

http://www.vmware.com/download/server/

------- Comment #1 From Stefan Behte 2008-06-04 17:31:07 0000 -------
This is for security also, I didn't see the message earlier, sorry!
VMSA-2008-0009
(http://lists.grok.org.uk/pipermail/full-disclosure/2008-June/062651.html)
VMware VIX Application Programming Interface (API) Memory Overflow

The worst one:
The VIX API (also known as "Vix") is an API that lets users write scripts
and programs to manipulate virtual machines.

Multiple buffer overflow vulnerabilities are present in the VIX API.
Exploitation of these vulnerabilities might result in code execution on
the host system or on the service console in ESX Server from the guest
operating system.

-> it allows you to escape from the VM, that's exactly what you don't want at
all!

vmware-server-1.0.6.91891 implements those fixes, but we also need to update
app-emulation/vmware-player and app-emulation/vmware-workstation ASAP!

------- Comment #2 From Mike Auty 2008-06-04 22:09:13 0000 -------

*** This bug has been marked as a duplicate of bug 224637 ***

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug