Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 224861 - version bump: app-emulation/vmware-server-1.0.6.91891
Summary: version bump: app-emulation/vmware-server-1.0.6.91891
Status: RESOLVED DUPLICATE of bug 224637
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo VMWare Bug Squashers [disabled]
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-06-04 09:28 UTC by Stefan Behte (RETIRED)
Modified: 2008-06-04 22:09 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2008-06-04 09:28:15 UTC
Hi, it's available since 5/29/08 and as there was no ticket open, I was so outrageous and created this bugtracker entry ;)

http://www.vmware.com/download/server/
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2008-06-04 17:31:07 UTC
This is for security also, I didn't see the message earlier, sorry!
VMSA-2008-0009 (http://lists.grok.org.uk/pipermail/full-disclosure/2008-June/062651.html)
VMware VIX Application Programming Interface (API) Memory Overflow

The worst one:
The VIX API (also known as "Vix") is an API that lets users write scripts
and programs to manipulate virtual machines.

Multiple buffer overflow vulnerabilities are present in the VIX API.
Exploitation of these vulnerabilities might result in code execution on
the host system or on the service console in ESX Server from the guest
operating system.

-> it allows you to escape from the VM, that's exactly what you don't want at all!

vmware-server-1.0.6.91891 implements those fixes, but we also need to update app-emulation/vmware-player and app-emulation/vmware-workstation ASAP!


Comment 2 Mike Auty (RETIRED) gentoo-dev 2008-06-04 22:09:13 UTC

*** This bug has been marked as a duplicate of bug 224637 ***