Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 211574 - app-emulation/vmware-player, vmware-workstation: Shared Folders Directory Traversal (CVE-2008-0923)
Summary: app-emulation/vmware-player, vmware-workstation: Shared Folders Directory Tra...
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor
Assignee: Gentoo Security
URL: http://www.coresecurity.com/?action=i...
Whiteboard: B3 [upstream]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-02-26 22:43 UTC by Robert Buchholz (RETIRED)
Modified: 2008-02-26 23:10 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-02-26 22:43:20 UTC
CVE-2008-0923 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0923):
  Directory traversal vulnerability in the Shared Folders feature for VMWare
  ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2
  allows guest OS users to read and write arbitrary files on the host OS via a
  multibyte string that produces a wide character string containing .. (dot
  dot) sequences, which bypasses the protection mechanism, as demonstrated
  using a "%c0%2e%c0%2e" string.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-02-26 22:50:25 UTC
Upstream failed to provide an update to their products since November, now this is public.
We can either mask, wait, or send an advisory with the "disable shared folder" workaround.
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-02-26 23:10:23 UTC
Good news: Vmware upstream states that only windows-hosted machines are affected, i.e. not an issue for us. Thanks to nion for pointing that out for me.

http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1004034