Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 265139 (CVE-2009-0909) - <app-emulation/vmware-{workstation,player}-*.5.2.156735, <app-emulation/vmware-server-1.0.9-156507: Execution of arbitrary code (CVE-2009-{0909,0910,1244})
Summary: <app-emulation/vmware-{workstation,player}-*.5.2.156735, <app-emulation/vmwar...
Status: RESOLVED FIXED
Alias: CVE-2009-0909
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.vmware.com/security/adviso...
Whiteboard: B2 [glsa]
Keywords:
: 269163 (view as bug list)
Depends on: 264948
Blocks:
  Show dependency tree
 
Reported: 2009-04-06 19:08 UTC by Alex Legler (RETIRED)
Modified: 2012-09-29 16:26 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2009-04-06 19:08:01 UTC
CVE-2009-0909 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0909):
  Heap-based buffer overflow in the VNnc Codec in VMware Workstation
  6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2
  build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware
  Server 2.0.x before 2.0.1 build 156745 allows remote attackers to
  execute arbitrary code via a crafted web page or video file, aka
  ZDI-CVE-435.

CVE-2009-0910 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0910):
  Heap-based buffer overflow in the VNnc Codec in VMware Workstation
  6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2
  build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware
  Server 2.0.x before 2.0.1 build 156745 allows remote attackers to
  execute arbitrary code via a crafted web page or video file, aka
  ZDI-CVE-436.

Affected are     : Resolved in
Workstation 6.5.x: 6.5.2 build 156735 or later
Player      2.5.x: 2.5.X build 156735 or later
Comment 1 Mike Auty (RETIRED) gentoo-dev 2009-04-06 21:41:38 UTC
Ok, the necessary ebuilds are now in the tree (vmware-server is only up to 1.0.8 in the tree.  2.0.0 existed in the vmware overlay, but has been updated to 2.0.1 there).  Over to you guys...
Comment 2 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-04-07 06:06:54 UTC
(In reply to comment #1)
> Over to you guys...

*passes the ball again*

Arches, please test and mark stable:
=app-emulation/vmware-workstation-6.5.2.156735
=app-emulation/vmware-player-2.5.2.156735
Target keywords : "amd64 x86"
Comment 3 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-04-13 23:14:30 UTC
CVE-2009-1244 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1244):
  Unspecified vulnerability in the virtual machine display function in
  VMware Workstation 6.5.1 and earlier; VMware Player 2.5.1 and
  earlier; VMware ACE 2.5.1 and earlier; VMware Server 1.x before 1.0.9
  build 156507 and 2.x before 2.0.1 build 156745; VMware Fusion before
  2.0.4 build 159196; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and
  3.5 allows guest OS users to execute arbitrary code on the host OS
  via unknown vectors, a different vulnerability than CVE-2008-4916.

Comment 4 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-04-14 19:41:21 UTC
Mike, the in-tree vmware-server is vulnerable to that third new issue. Please bump to "1.0.9 build 156507 or later".

Reference: http://www.vmware.com/security/advisories/VMSA-2009-0006.html
Comment 5 Mike Auty (RETIRED) gentoo-dev 2009-04-14 21:23:15 UTC
Yep, I spotted it, and I've got versions ready to get tested in the overlay, but I need to sort out the modules first (since the ones we're using don't compile under the latest kernel and hopefully the ones that come with 1.0.9 will).  I estimate I should have something workable in the overlay if not the tree by the weekend.  I'll keep you updated, but please don't let it hold back the workstation bits and pieces...
Comment 6 Christian Faulhammer (RETIRED) gentoo-dev 2009-05-05 05:34:09 UTC
(In reply to comment #2)
> =app-emulation/vmware-workstation-6.5.2.156735

 I cannot download that version from the VMWare pages...the only version available for me is 2.5.1.
 For the player I need a KVM-disabled kernel.  After the next reboot...
Comment 7 Mike Auty (RETIRED) gentoo-dev 2009-05-05 08:23:43 UTC
Do you mean 2.5.2 rather than 2.5.1?
Comment 8 Christian Faulhammer (RETIRED) gentoo-dev 2009-05-05 08:39:58 UTC
(In reply to comment #7)
> Do you mean 2.5.2 rather than 2.5.1?

 Sorry I meant:

Version 6.5.1 | 126130
Comment 9 Mike Auty (RETIRED) gentoo-dev 2009-05-05 08:42:23 UTC
Try http://www.vmware.com/download/download.do?downloadGroup=WKST-652-LX, which should be the top link from http://www.vmware.com/download/ws/...
Comment 10 Christian Faulhammer (RETIRED) gentoo-dev 2009-05-05 10:42:58 UTC
-workstation and -player stable on x86
Comment 11 Gordon Malm (RETIRED) gentoo-dev 2009-05-09 17:00:36 UTC
*** Bug 269163 has been marked as a duplicate of this bug. ***
Comment 12 Mike Auty (RETIRED) gentoo-dev 2009-05-09 22:01:50 UTC
Ok, Gengor very kindly tested out vmware-server-1.0.9 for me, and says it works with the existing modules, so I've committed it (and vmware-server-console-1.0.9) to the tree.  I moved vmware-server-2 in at the same time, since it's been sitting around for too long.  Please only bother stabilizing 1.0.9, 2.0.1 needs much more time to work out the kinks...
Comment 13 Stefan Behte (RETIRED) gentoo-dev Security 2009-06-22 18:10:19 UTC
*Ping to arches*
Comment 14 Christian Faulhammer (RETIRED) gentoo-dev 2009-06-25 14:16:27 UTC
x86 stable
Comment 15 Markus Meier gentoo-dev 2009-07-30 21:16:54 UTC
amd64 stable, all arches done.
Comment 16 Tobias Heinlein (RETIRED) gentoo-dev 2009-07-30 22:55:24 UTC
GLSA together with all the other bugs...
Comment 17 Tobias Heinlein (RETIRED) gentoo-dev 2009-07-30 23:31:30 UTC
amd64 ping, you missed vmware-server-1.0.9-156507.
Comment 18 Markus Meier gentoo-dev 2009-08-01 14:25:15 UTC
amd64 stable, all arches done.
Comment 19 Stefan Behte (RETIRED) gentoo-dev Security 2009-08-01 15:11:44 UTC
Thanks everyone, this will be added to an already pending glsa.
Comment 20 Jaak Ristioja 2010-07-23 09:04:05 UTC
There is no <app-emulation/vmware-workstation-5.5.9.126128 nor <app-emulation/vmware-server-1.0.9.156507 in portage any more. I'm not sure about vmware-player.
Comment 21 GLSAMaker/CVETool Bot gentoo-dev 2012-09-29 16:26:23 UTC
This issue was resolved and addressed in
 GLSA 201209-25 at http://security.gentoo.org/glsa/glsa-201209-25.xml
by GLSA coordinator Sean Amoss (ackle).